CVE-2026-78849: Netgate pfSense Plus vulnerability
Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captiveportalstatus.widget.php file
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the Cross Site Scripting issue by removing/blocking access to the captive_portal_status.widget.php endpoint (captive_portal_status.widget.php is the file identified as allowing a remote attacker to execute arbitrary code) for the affected pfSense Plus versions <= 26.03 and pfSense CE versions <= 2.8.1.
Event History
Frequently Asked Questions
Which pfSense editions and versions are affected?
The issue affects Netgate pfSense Plus through version 26.03 and pfSense CE through version 2.8.1.
What component is involved in the vulnerability?
The vulnerable component is the captive_portal_status.widget.php file.
Can the issue be exploited remotely?
Yes. The vulnerability is described as allowing a remote attacker to execute arbitrary code.