CVE-2026-56126 | Netgate pfSense Plus/pfSense CE Monitoring page status_monitoring.php injection

SecurityVulns

A vulnerability, which was classified as critical, was found in Netgate pfSense Plus and pfSense CE. Affected by this vulnerability is an unknown functionality of the file status_monitoring.php of the component Monitoring page. The manipulation of the argument graph-left/graph-right/time-period/resolution/start-date/end-date/start-time/end-time/graph-type/invert/refresh-interval results in injection.

This vulnerability is reported as CVE-2026-56126. The attack can be launched remotely. No exploit exists.VulDB Recent EntriesRead More