What is CVE-2026-67189?
CVE-2026-67189 is a stored cross-site scripting vulnerability in pfSense Plus before 26.07 and pfSense CE through 2.8.1, affecting the Traffic Graphs top-talkers feature. Unsanitized PTR records from reverse DNS lookups are incorporated into AJAX responses and rendered as HTML via a DOM sink. Users should update to the latest version to mitigate the risk of malicious script execution.
Azərbaycanca: CVE-2026-67189 pfSense Plus (26.07-dən əvvəl) və pfSense CE (2.8.1 daxil olmaqla) platformalarında 'Traffic Graphs top-talkers' funksiyasında aşkarlanmış stored XSS zəifliyidir. Bu zəiflik üzündən əks DNS sorğularından gələn PTR qeydləri təmizlənmədən AJAX cavablarına daxil edilir və HTML olaraq işlənir. İstifadəçilər bu boşluq vasitəsilə təhlükəli skriptlərin icrasına məruz qala bilər, ona görə də dərhal proqramı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of pfSense are affected by CVE-2026-67189?
pfSense Plus before 26.07 and pfSense CE through 2.8.1.
What is the root cause of the CVE-2026-67189 stored XSS vulnerability?
Unsanitized PTR records from reverse DNS lookups are incorporated into AJAX responses and rendered as HTML via a DOM sink.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.