CVE-2026-95165: XSS
Published Oct 5, 2026
·Updated
Bacularis 5.4.0 - 6.5.1 is vulnerable to Cross Site Scripting (XSS) in the Organization name field.
Affected Software
1 affected component
Bacularis Bacularis>=5.4.0<=6.5.1
Event History
Oct 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are affected?
Bacularis versions 5.4.0 through 6.5.1 are identified as affected. The available information does not state whether any configuration or deployment mode is exempt.
2
What input must an attacker control to exploit this issue?
An attacker must be able to set an Organization name containing cross-site scripting payload content. The available information does not specify the required user role, authentication status, or where that field is exposed.
3
How can I determine whether my instance may be affected?
Check whether the Bacularis version is between 5.4.0 and 6.5.1 and whether Organization name values can contain and later render unescaped user-controlled content. The provided information does not include a detection method or indicators of compromise.