---
id: CVE-2026-92860
title: A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4
summary: >-
  A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4.
  Affected by this issue is the function fmt.Sprintf of the file
  /api/security/quick-setup of the component Quick Security Setup Handler. The
  manipulation of th…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: rcourtman
product: Pulse
affected:
  - Pulse 6.0.0
  - Pulse 6.0.1
  - Pulse 6.0.2
  - Pulse 6.0.3
  - Pulse 6.0.4
  - Pulse 6.1.0-rc.0
  - Pulse 6.1.0-rc.1
  - Pulse 6.1.0-rc.2
  - Pulse 6.1.0-rc.3
  - Pulse 6.1.0-rc.4
published: '2026-09-17'
updated: '2026-09-19'
sourceUpdated: '2026-09-19T03:17:17.877'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92860'
references:
  - url: 'https://github.com/rcourtman/Pulse/'
    label: cna@vuldb.com
  - url: 'https://github.com/rcourtman/Pulse/releases/tag/v6.1.0'
    label: cna@vuldb.com
  - url: 'https://github.com/rcourtman/Pulse/security/advisories/GHSA-rr3f-jjrr-3qxv'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-92860'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/941807'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/406309'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/406309/cti'
    label: cna@vuldb.com
  - url: 'https://github.com/rcourtman/Pulse/security/advisories/GHSA-rr3f-jjrr-3qxv'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00853
epssPercentile: 0.56464
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-19T02:17:24.085914Z'
ingestedAt: '2026-09-17T12:16:56.807Z'
---

## Overview

A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the component Quick Security Setup Handler. The manipulation of the argument Username results in improper input validation. The attack may be performed from remote. Upgrading the affected component is advised.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
