CVE-2026-95166: XSS
Published Oct 5, 2026
·Updated
In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload.
Affected Software
1 affected component
Bacularis Bacularis>=1.0.0<=6.5.1
Event History
Oct 5, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What attacker access is required to exploit this issue?
An attacker needs access to add a new pool and control the LabelFormat field. The provided data does not indicate whether lower-privileged users can create pools.
2
Which releases are identified as affected?
Bacularis versions 1.0.0 through 6.5.1 are identified as affected.