CVE-2026-38961
Received Received - Intake

Cross-Site Scripting in Netgate pfSense RSS Widget

Vulnerability report for CVE-2026-38961, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-04

Last updated on: 2026-09-04

Assigner: MITRE

Description

Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense CE (version 2.8.1) allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user who views the dashboard, due to insufficient sanitization of feed title data before rendering in the widget.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-04
Last Modified
2026-09-04
Generated
2026-09-05
AI Q&A
2026-09-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
netgate pfsense_plus 26.03
netgate pfsense_plus 25.11.1
netgate pfsense_ce 2.8.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus and pfSense CE. It allows remote authenticated attackers to inject arbitrary JavaScript via malicious content in an RSS feed title. The injected script executes in the browser of any authenticated user viewing the dashboard due to insufficient sanitization of feed title data before rendering.

Detection Guidance

To detect this XSS vulnerability in pfSense, inspect the RSS widget on the dashboard for unusual or malicious JavaScript content in feed titles. Check browser developer tools for unexpected script execution when viewing the dashboard. No specific commands are provided, but manual inspection of widget output is recommended.

Impact Analysis

An attacker could steal session cookies, perform actions on behalf of users, or redirect users to malicious sites. Any authenticated user viewing the dashboard with the vulnerable RSS widget could be affected.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR (data protection) and HIPAA (health information privacy) requirements. It may result in data breaches, non-compliance penalties, and loss of trust.

Mitigation Strategies

Immediately update pfSense to the latest patched version (26.03.1, 25.11.2, or 2.8.2). Disable the RSS widget if not required. If updates are unavailable, restrict dashboard access to trusted users only and monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-38961. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart