CVE-2026-92860 | rcourtman Pulse up to 6.0.4/6.1.0-rc.4 Quick Security Setup quick-setup fmt.Sprintf Username input validation (GHSA-rr3f-jjrr-3qxv)
A vulnerability classified as very critical was found in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the component Quick Security Setup Handler. The manipulation of the argument Username results in improper input validation.
This vulnerability was named CVE-2026-92860. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.VulDB Recent EntriesRead More