OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97730

HIGH · CVSS 8.5 EPSS 1.03% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

A Local File Inclusion (LFI) vulnerability in the Dashboard widget sequence handling of Netgate pfSense Plus and pfSense CE allows authenticated attackers with sufficient privileges to execute arbitrary PHP code on the firewall system. By manipulating widget sequence values to include path traversal payloads, attackers can read and execute malicious files, potentially compromising the integrity of the system. Organizations using affected versions of pfSense should prioritize patching this vulnerability to mitigate the risk of unauthorized code execution.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-97730
Severity
HIGH
CVSS
8.5
EPSS
1.03%

Original NVD Description

In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dashboard (index.php) widget sequence data handling allows an authenticated attacker to execute arbitrary PHP code. To exploit this, an attacker with privileges to modify Dashboard settings and write arbitrary files to the pfSense firewall system (e.g., /tmp/test.widget.php) can submit a crafted widget sequence value containing a path traversal payload (e.g., ../../../../../../../../../../../tmp/test). The Dashboard will subsequently read and execute the arbitrary PHP file as if it were a standard widget.