Improper Input Validation in rcourtman Pulse Quick Security Setup Component
CVE-2026-92860
9.4CRITICAL
What is CVE-2026-92860?
A security flaw has been identified in the rcourtman Pulse product, specifically within the Quick Security Setup component. The issue arises in the fmt.Sprintf function located in the /api/security/quick-setup file, where improper validation of the Username parameter could allow an attacker to exploit this flaw remotely. It is recommended that users upgrade to a secure version to mitigate potential threats associated with this vulnerability.
Affected Version(s)
Pulse 6.0.0
Pulse 6.0.1
Pulse 6.0.2
