CVE-2026-88743
[ RESEARCH ] - CVE-2026-88743 - Stored XSS in Bacularis 4.7.0 - 6.5.0 - director tags
·446 words·3 mins
RESEARCH
CVE-2026-88743
BACULARIS
Stored XSS affects all users via globally accessible tags. Add a global tag in JobDefs and set its value to an XSS payload. Once assigned, it executes for every user who can view jobs.