PatchSiren

rcourtman CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL rcourtman CVE published 2026-09-17

CVE-2026-92860

A critical vulnerability was discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4, affecting the Quick Security Setup Handler. The issue lies in improper input validation in the function fmt.Sprintf of the file /api/security/quick-setup, specifically with the Username argument. This vulnerability can be exploited remotely, and upgrading the affected component is advised.