OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92860

CRITICAL · CVSS 9.1 EPSS 0.85% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the Quick Security Setup Handler of rcourtman Pulse versions up to 6.0.4/6.1.0-rc.4, where improper input validation in the Username argument can be exploited remotely. This flaw could allow attackers to manipulate input, potentially leading to unauthorized access or other malicious activities. Organizations using these versions should prioritize upgrading to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-92860
Severity
CRITICAL
CVSS
9.1
EPSS
0.85%

Original NVD Description

A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the component Quick Security Setup Handler. The manipulation of the argument Username results in improper input validation. The attack may be performed from remote. Upgrading the affected component is advised.