<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Pulse (&lt; 6.0.4/6.1.0-Rc.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/pulse--6.0.4/6.1.0-rc.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 17 Sep 2026 13:56:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/pulse--6.0.4/6.1.0-rc.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution via Improper Input Validation in rcourtman Pulse</title><link>https://feed.craftedsignal.io/briefs/2026-09-pulse-input-validation/</link><pubDate>Thu, 17 Sep 2026 13:56:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-pulse-input-validation/</guid><description>An improper input validation vulnerability in the rcourtman Pulse Quick Security Setup Handler allows remote attackers to perform arbitrary operations via the Username argument.</description><content:encoded><![CDATA[<p>A high-severity security vulnerability, identified as CVE-2026-92860, has been disclosed in the rcourtman Pulse application. The flaw resides within the Quick Security Setup Handler, specifically affecting the fmt.Sprintf function inside the /api/security/quick-setup endpoint. The vulnerability is caused by improper input validation of the Username argument, which can be manipulated by a remote, unauthenticated attacker. This flaw poses a significant risk to affected installations, as it potentially allows for remote code execution or unauthorized system manipulation. The issue affects all versions of rcourtman Pulse up to 6.0.4 and 6.1.0-rc.4. Organizations running these versions are advised to upgrade immediately to a patched release once available to mitigate the risk of remote exploitation.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 base score of 9.1, indicating a critical risk of full system compromise for internet-facing installations. Successful exploitation allows remote attackers to bypass security controls by injecting malicious payloads into the Username field during the quick setup process, potentially leading to unauthorized data access, system disruption, or complete control over the host running the Pulse software.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the upgrade of all internet-facing instances of rcourtman Pulse to a version beyond 6.0.4 or 6.1.0-rc.4. Detection engineering teams should monitor web server logs for suspicious or unusually long strings contained within the Username parameter of POST requests directed at /api/security/quick-setup.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>