Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 25 Sep 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local File Inclusion in pfSense Dashboard Allows Arbitrary PHP Execution |
Fri, 25 Sep 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netgate
Netgate pfsense Ce Netgate pfsense Plus |
|
| Vendors & Products |
Netgate
Netgate pfsense Ce Netgate pfsense Plus |
Fri, 25 Sep 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write arbitrary files to the pfSense firewall system (e.g., /tmp/test.widget.php) can submit a crafted widget sequence value containing a path traversal payload (e.g., ../../../../../../../../../../../tmp/test). The Dashboard will subsequently read and execute the arbitrary PHP file as if it were a standard widget. | |
| Weaknesses | CWE-24 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-25T02:43:13.541Z
Reserved: 2026-09-25T02:43:12.840Z
Link: CVE-2026-97730
No data.
Status : Received
Published: 2026-09-25T03:16:59.533
Modified: 2026-09-25T03:16:59.533
Link: CVE-2026-97730
No data.
OpenCVE Enrichment
Updated: 2026-09-25T09:00:14Z
-
CWE-24
Path Traversal: '../filedir'