CVE-2026-88742

Bacularis 1.0.0 - 6.5.0 is vulnerable to Stored cross-site scripting (XSS) in the client address field.

  • Published Sep 15, 2026
  • CVSS 5.4 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

CVE-2026-88742 at the National Vulnerability Database