Bug 2451432 (CVE-2026-1001) - CVE-2026-1001 Domoticz: Domoticz: Arbitrary script execution via stored cross-site scripting in web interface
Summary: CVE-2026-1001 Domoticz: Domoticz: Arbitrary script execution via stored cross...
Keywords:
Status: NEW
Alias: CVE-2026-1001
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2451506 2451507 2451508 2451509
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-25 19:01 UTC by OSIDB Bzimport
Modified: 2026-03-25 21:40 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-03-25 19:01:56 UTC
Domoticz versions prior to 2026.1 contain a stored cross-site scripting vulnerability in the Add Hardware and rename device functionality of the web interface that allows authenticated administrators to execute arbitrary scripts by supplying crafted names containing script or HTML markup. Attackers can inject malicious code that is stored and rendered without proper output encoding, causing script execution in the browsers of users viewing the affected page and enabling unauthorized actions within their session context.


Note You need to log in before you can comment on or make changes to this bug.