Junglewise Threat Intelligence

CVE-2026-92860: rcourtman Pulse improper input validation in Quick Security Setup

CVE-2026-92860 · Severity: critical · CVSS 9.1 · Published 2026-09-17

Executive brief

Pulse is a real-time monitoring dashboard for virtualization and containerization platforms. A flaw in the Quick Security Setup handler allows remote attackers to exploit improper input validation in the username field, potentially bypassing authentication or injecting malicious commands without requiring prior access.

Technical details

The vulnerability exists in the Quick Security Setup Handler component at the /api/security/quick-setup endpoint, where the fmt.Sprintf function is improperly used to process the Username argument. This results in improper input validation that could allow format string injection or similar attacks. The flaw is remotely exploitable without authentication requirements and affects versions up to 6.0.4 and release candidates through 6.1.0-rc.4. Upgrading to a patched version is recommended.

Affected products

  • rcourtman Pulse up to 6.0.4 and 6.1.0-rc.4

Timeline

  • 2026-09-17: disclosed

References