Impact
Domoticz versions before 2026.3 expose a stored cross‑site scripting flaw in the mobile dashboard. An authenticated attacker can send an API request to update a Text or Alert subtype device with malicious HTML or JavaScript. When an administrator later views the mobile dashboard, the payload is rendered through ng‑bind‑html with only nl2br() applied, meaning no escaping occurs. This results in arbitrary script execution within the administrator’s browser, allowing cookie theft and account takeover.
Affected Systems
The vulnerability affects the Domoticz application, specifically all releases prior to version 2026.3. No other vendors or product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 2 indicates a low base severity in the scoring model, but the real risk is higher because the flaw is abused only by authenticated users who can modify device values. The EPSS score is not available, and the flaw is not listed in the CISA KEV catalog, which suggests it has not yet been widely exploited. The likely attack vector is an authenticated API request that updates device values, followed by an administrator visiting the mobile dashboard. While exploitation requires valid credentials, the potential impact on staff accounts means that the vulnerability should be treated with priority.
OpenCVE Enrichment