Description
A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the component Quick Security Setup Handler. The manipulation of the argument Username results in improper input validation. The attack may be performed from remote. Upgrading the affected component is advised.
Published: 2026-09-17
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Pulse contains a format-string vulnerability in the Quick Security Setup handler. The fmt.Sprintf function is called with a Username value supplied by a caller. Because no validation or sanitization is performed, malicious format specifiers can be embedded in that value. If an attacker sends such a request, the formatter will process the specifiers, potentially yielding remote code execution or leaking sensitive data from the server.

Affected Systems

Affected are rcourtman Pulse versions up to 6.0.4 and 6.1.0-rc.4. The vulnerability resides in the /api/security/quick-setup endpoint handled by the Quick Security Setup component.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity. EPSS is not available, so the real‑world exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, yet the description explicitly states that the attack may be performed from remote hosts. Because the flaw results from improper input validation (CWE-20) and exploits the Go fmt.Sprintf implementation, remote attackers can inject format strings that cause code execution on the server. The vendor recommends upgrading to Pulse 6.1.0 or later to obtain the fix.

Generated by OpenCVE AI on September 18, 2026 at 07:14 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Pulse to version 6.1.0 or later, which contains the fix for the format-string vulnerability.
  • Validate the Username input in the /api/security/quick-setup endpoint to ensure it does not contain format specifiers before it is passed to fmt.Sprintf.
  • Limit exposure of the Quick Security Setup API endpoint by applying firewall or access control rules to allow only trusted clients.

Generated by OpenCVE AI on September 18, 2026 at 07:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the component Quick Security Setup Handler. The manipulation of the argument Username results in improper input validation. The attack may be performed from remote. Upgrading the affected component is advised.
Title rcourtman Pulse Quick Security Setup quick-setup fmt.Sprintf input validation
First Time appeared Rcourtman
Rcourtman pulse
Weaknesses CWE-20
CPEs cpe:2.3:a:rcourtman:pulse:*:*:*:*:*:*:*:*
Vendors & Products Rcourtman
Rcourtman pulse
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-19T02:17:54.387Z

Reserved: 2026-09-17T05:45:33.939Z

Link: CVE-2026-92860

cve-icon Vulnrichment

Updated: 2026-09-19T02:17:42.520Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T12:18:29.927

Modified: 2026-09-19T03:17:17.877

Link: CVE-2026-92860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation