{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3arcourtmanpulse/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rcourtman:pulse:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-92860"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Pulse (\u003c 6.0.4/6.1.0-rc.4)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["rcourtman"],"content_html":"\u003cp\u003eA high-severity security vulnerability, identified as CVE-2026-92860, has been disclosed in the rcourtman Pulse application. The flaw resides within the Quick Security Setup Handler, specifically affecting the fmt.Sprintf function inside the /api/security/quick-setup endpoint. The vulnerability is caused by improper input validation of the Username argument, which can be manipulated by a remote, unauthenticated attacker. This flaw poses a significant risk to affected installations, as it potentially allows for remote code execution or unauthorized system manipulation. The issue affects all versions of rcourtman Pulse up to 6.0.4 and 6.1.0-rc.4. Organizations running these versions are advised to upgrade immediately to a patched release once available to mitigate the risk of remote exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS v3.1 base score of 9.1, indicating a critical risk of full system compromise for internet-facing installations. Successful exploitation allows remote attackers to bypass security controls by injecting malicious payloads into the Username field during the quick setup process, potentially leading to unauthorized data access, system disruption, or complete control over the host running the Pulse software.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of all internet-facing instances of rcourtman Pulse to a version beyond 6.0.4 or 6.1.0-rc.4. Detection engineering teams should monitor web server logs for suspicious or unusually long strings contained within the Username parameter of POST requests directed at /api/security/quick-setup.\u003c/p\u003e\n","date_modified":"2026-09-17T13:56:42Z","date_published":"2026-09-17T13:56:42Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pulse-input-validation/","summary":"An improper input validation vulnerability in the rcourtman Pulse Quick Security Setup Handler allows remote attackers to perform arbitrary operations via the Username argument.","title":"Remote Code Execution via Improper Input Validation in rcourtman Pulse","url":"https://feed.craftedsignal.io/briefs/2026-09-pulse-input-validation/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:rcourtman:pulse:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}