Junglewise Threat Intelligence

CVE-2026-1001: Domoticz stored XSS in Add Hardware and rename device functionality

CVE-2026-1001 · Severity: medium · CVSS 4.8 · Published 2026-03-25

Executive brief

Domoticz, an open-source home automation system, is vulnerable to a security flaw where malicious scripts can be embedded into device and hardware names. An attacker with administrative access could use this to target other users of the system, potentially leading to unauthorized actions or session hijacking when those users view the management interface. This issue is resolved in version 2026.1.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Domoticz versions prior to 2026.1 within the 'Add Hardware' and device renaming functionality. The vulnerability is caused by improper output encoding of user-supplied names, allowing an authenticated administrator to inject malicious HTML or JavaScript. The attack requires high privileges (PR:H) and some user interaction (UI:P) from other users viewing the affected configuration pages. Successful exploitation allows for arbitrary script execution within the context of the victim's browser session. The issue is addressed in the 2026.1 release.

Affected products

  • Domoticz Domoticz prior to 2026.1

Timeline

  • 2026-03-25: disclosed
  • 2026-03-25: patched: Fixed in version 2026.1
  • 2026-03-25: advisory

References