↓Skip to main content

CVE-2026-95166

[ RESEARCH ] - CVE-2026-95166 - Stored XSS in Bacularis 1.0.0 - 6.5.1 - Pool LabelFormat field
·168 words·1 min
RESEARCH CVE-2026-95166 BACULARIS
Stored XSS affects admins or users with PoolList/PoolView. Add an XSS payload to labelFormat in Pools / Add pool; it executes when viewing pool details and running Update pool.