CVE-2026-78849 Details
Description
Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.8.1 allows a remote attacker to execute arbitrary code via the captive_portal_status.widget.php file
A stored cross-site scripting vulnerability has been identified in Netgate pfSense Plus software versions prior to 26.03 and pfSense CE software versions prior to 2.8.1. The issue resides in the Captive Portal Dashboard widget, specifically within the 'captive_portal_status.widget.php' file. When Captive Portal is configured for unauthenticated access, a remote attacker can execute arbitrary code by sending a crafted username containing an XSS payload via the 'auth_user' parameter. The vulnerability arises because the Captive Portal does not validate or encode the username before displaying it on the dashboard, allowing for the execution of malicious scripts in the user's browser.
Users can upgrade to pfSense Plus version 26.07 or later, or pfSense CE version 2.9.0 or later. For users on pfSense Plus versions 26.03 or 25.11.1, and pfSense CE version 2.8.1, the fix is available through the System Patches package. Visit the Netgate pfSense upgrade guide for more details.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 4, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://redmine.pfsense.org/attachments/6991 | CISA-ADP | ExploitIssue TrackingVendor |
| https://docs.netgate.com/downloads/pfSense-SA-26_05.webgui.asc | [email protected] | AdvisoryRemedyVendor |
| https://redmine.pfsense.org/issues/16773 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Netgate pfSense Plus | <= 26.03 |
CPE
Remediation
| |
| Netgate pfSense CE | <= 2.8.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 4, 2026 | New CVE Received | [email protected] |
Volerion