CVE-2026-97730

LOWCVSS 8.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write arbitrary files to the pfSense firewall system (e.g., /tmp/test.widget.php) can submit a crafted widget sequence value containing a path traversal payload (e.g., ../../../../../../../../../../../tmp/test). The Dashboard will subsequently read and execute the arbitrary PHP file as if it were a standard widget.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-24

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-09-25: 309-25
Referenced assets2 URLs
Full discourse3 posts
  • CyberSignal | Cybersecurity & AI News@XQOPTRX

    🚨 NEW PFSENSE VULNERABILITY CAN LEAD TO ARBITRARY PHP CODE EXECUTION A new vulnerability was published today affecting Netgate pfSense. Tracked as: CVE-2026-97730 CVSS: 8.5 HIGH Affected versions include: pfSense Plus before 26.07 and pfSense CE before 2.9.0. The vulnerability involves local-file inclusion in the pfSense dashboard widget-sequence handling. Under the required conditions, an authenticated attacker able to modify dashboard settings and place a file on the firewall can use path traversal to cause pfSense to load an arbitrary PHP file as a dashboard widget. That can result in arbitrary PHP-code execution. Important limitation: This is not an unauthenticated internet RCE. The attacker needs specific authenticated privileges and the ability to place a file on the system. But pfSense often occupies an extremely privileged position in enterprise networks. Compromise of a firewall-management plane can expose: network configuration VPN infrastructure routing credentials security policies internal network visibility. 🛡️ Upgrade to the vendor-fixed release where applicable. Sources: CVE record · Netgate references · Vulners.

    0103064
    228 followersView on X
  • Severity Daily@severitydaily

    Netgate's pfSense CVE published this morning names CE 2.9.0 as the fixed version. The latest pfSense CE you can download is 2.8.1. Authenticated dashboard access to arbitrary PHP, no exploitation reported. https://severitydaily.com/pfsense-cve-2026-97730-dashboard-lfi-ce-2-9-0-not-released/

    1000027
    24 followersView on X
  • ADK Cyber@ADKCyber

    pfSense users: CVE-2026-97730 (CVSS 8.5) is a high-severity LFI flaw in dashboard widgets. Apply updates to Plus 26.07+ or CE 2.9.0+ soon. https://nvd.nist.gov/vuln/detail/CVE-2026-97730 via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/9NwSyzScJm

    0000030
    97 followersView on X

Explore more