CVE-2026-88742: XSS
Published Sep 15, 2026
·Updated
Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.
Affected Software
1 affected component
Bacularis Bacularis>=1.0.0<=6.5.0
Event History
Sep 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are affected?
Bacularis versions 1.0.0 through 6.5.0 are identified as affected. The available information does not state any configuration-specific limitations.
2
What input should be reviewed during triage?
Review values stored in the client address field, which is the identified injection point. The provided data does not specify the required privileges, execution context, or a mitigation for unpatched systems.