CVE-2026-95166
[ RESEARCH ] - CVE-2026-95166 - Stored XSS in Bacularis 1.0.0 - 6.5.1 - Pool LabelFormat field
·168 words·1 min
RESEARCH
CVE-2026-95166
BACULARIS
Stored XSS affects admins or users with PoolList/PoolView. Add an XSS payload to labelFormat in Pools / Add pool; it executes when viewing pool details and running Update pool.