Description
In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload.
Published: 2026-10-05
Score: n/a
EPSS: n/a
KEV: No
Impact: Cross‑Site Scripting (client‑side) that can subvert user sessions
Action: Patch
AI Analysis

Impact

A flaw in the LabelFormat field of Bacularis appears when a new pool is added. The application fails to sanitize or escape the string, allowing an attacker to inject a Cross‑Site Scripting payload. If a user interacts with the vulnerable webpage, the malicious script can read or modify the browser’s state, steal authentication cookies, or perform actions on behalf of that user. The effect is limited to the victim’s browser session and does not provide system‑level privileges.

Affected Systems

The issue affects the Bacularis software in versions 1.0.0 through 6.5.1. Any deployment running these releases and utilizing the pool‑creation feature is susceptible.

Risk and Exploitability

The CVSS score is not publicly provided, and the EPSS score is unavailable. The vulnerability is not yet listed in CISA’s KEV catalog. Exploitation requires access to the Bacularis web interface and a victim who will load the injected content. The risk is therefore constrained to users interacting with the interface, but the potential for credential theft and session hijacking is significant. If the application is exposed to untrusted clients, the impact could be amplified, especially when users rely on preserved authentication tokens.

Generated by OpenCVE AI on October 5, 2026 at 21:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Bacularis to a version beyond 6.5.1 where the LabelFormat field is properly sanitized.
  • Validate or sanitize input on the LabelFormat field, ensuring only safe characters or patterns are accepted.
  • If the LabelFormat feature is not required, disable it or limit it to trusted administrative accounts.

Generated by OpenCVE AI on October 5, 2026 at 21:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting via LabelFormat Field in Bacularis Pool Creation
Weaknesses CWE-79

Mon, 05 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-05T18:49:29.762Z

Reserved: 2026-09-22T00:00:00.000Z

Link: CVE-2026-95166

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T19:17:26.640

Modified: 2026-10-05T19:17:26.640

Link: CVE-2026-95166

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:15:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')