CVE-2026-95166
Received Received - Intake

Cross-Site Scripting (XSS) in Bacularis Pool Configuration

Vulnerability report for CVE-2026-95166, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MITRE

Description

In Bacularis v1.0.0 - 6.5.1 when adding a new pool, the LabelFormat field allows for a Cross Site Scripting (XSS) payload.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-95166 is a stored Cross-Site Scripting (XSS) vulnerability in Bacularis versions 1.0.0 to 6.5.1. It allows an attacker with admin or specific role privileges to inject a malicious script via the LabelFormat field in the Pools / Add pool section. The script executes when viewing pool details and triggering an Update pool action.

Detection Guidance

Check Bacularis versions between 1.0.0 and 6.5.1. Inspect the LabelFormat field in the Pools / Add pool section for any suspicious scripts or payloads. Review pool details and Update pool actions for unexpected script execution.

Impact Analysis

An attacker could steal session cookies, perform actions on behalf of users, or redirect users to malicious sites. This could lead to unauthorized access, data theft, or further compromise of the system if users interact with the infected pool details.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR's data protection requirements or HIPAA's safeguards for protected health information. Non-compliance may result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade Bacularis to version 6.5.2 or later immediately. Remove any untrusted scripts from the LabelFormat field in existing pools. Restrict administrator and PoolList/PoolView roles to trusted users only.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95166. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart