CVE-2026-78902: Crafted DNS Reply Enables XSS-to-RCE on pfSense

· Original article ↗

Summary

A flaw in pfBlockerNG on pfSense lets a crafted DNS reply trigger stored XSS when an administrator views Reports, potentially leading to root access. Netgate fixed the issue in pfBlockerNG 3.2.16_1.

Key points

  • The flaw affects pfBlockerNG on pfSense when DNS Reply Logging is enabled and the package is processing DNS requests in the described configuration.
  • An attacker can send a crafted DNS reply that is logged and later rendered unsafely in the pfSense web interface, enabling stored cross-site scripting.
  • If an administrator views the affected Reports page, attacker-controlled JavaScript can use pfSense's command-execution page to run commands and obtain a root shell.
  • The attack requires a DNS lookup from inside the network to pass through the affected resolver and an administrator to view the vulnerable report.
  • Netgate released pfBlockerNG version 3.2.16_1 on July 2, 2026, within a day of receiving the report; NetSPI says it tested the fix.

Article Details

Vulnerability Types
  • Stored cross-site scripting (XSS)
  • Remote code execution through the stored XSS attack chain
Severity
High-risk, according to NetSPI
Exploitation Status
reported
Exploit Availability
claimed_or_private
Patch Status
available

MITRE ATT&CK

CVE

Vendors

Products

Related Articles