Improper Input Validation in rcourtman Pulse Quick Security Setup Component
CVE-2026-92860

9.4CRITICAL

Key Information:

Vendor

Rcourtman

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92860?

A security flaw has been identified in the rcourtman Pulse product, specifically within the Quick Security Setup component. The issue arises in the fmt.Sprintf function located in the /api/security/quick-setup file, where improper validation of the Username parameter could allow an attacker to exploit this flaw remotely. It is recommended that users upgrade to a secure version to mitigate potential threats associated with this vulnerability.

Affected Version(s)

Pulse 6.0.0

Pulse 6.0.1

Pulse 6.0.2

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

wanyan (VulDB User)
.