CVE-2026-92860 Details
Description
A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the component Quick Security Setup Handler. The manipulation of the argument Username results in improper input validation. The attack may be performed from remote. Upgrading the affected component is advised.
A vulnerability in the rcourtman Pulse application, specifically in versions through 6.0.4 and 6.1.0-rc.4, has been identified within the Quick Security Setup Handler. The issue arises from improper input validation of the 'Username' field in the '/api/security/quick-setup' endpoint. This flaw allows authenticated administrative users to inject arbitrary systemd directives by exploiting the newline character, potentially leading to remote code execution with root privileges when the affected service is restarted.
Users are advised to upgrade to Pulse version 6.1.0, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 17, 2026CISA-ADP
Assessed Sep 19, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/rcourtman/Pulse/security/advisories/GHSA-rr3f-jjrr-3qxv | CISA-ADP | AdvisoryExploitRemedyVendor |
| https://github.com/rcourtman/Pulse/ | [email protected] | ProductSource CodeVendor |
| https://github.com/rcourtman/Pulse/releases/tag/v6.1.0 | [email protected] | Release NotesVendor |
| https://github.com/rcourtman/Pulse/security/advisories/GHSA-rr3f-jjrr-3qxv | [email protected] | AdvisoryExploitRemedyVendor |
| https://vuldb.com/cve/CVE-2026-92860 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/941807 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/406309 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/406309/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| rcourtman Pulse | <= 6.0.4 (semver) <= 6.1.0-rc.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 19, 2026 | CVE Modified | CISA-ADP |
| Sep 17, 2026 | New CVE Received | [email protected] |
Volerion