216.73.217.22

CVE-2026-45229

· Published 13/05/2026 21:16 · Modified 14/05/2026 16:24

Labels: CVE-2026-45229 2026-05-13CVE-2026-45229CWE-915[email protected]

Essential information

Published
13/05/2026 21:16
Modified
14/05/2026 16:24
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui object to the config_data dictionary. Attackers can exploit insufficient deny-list filtering to permanently replace stored login credentials, lock out legitimate administrators, and gain persistent access to all configured tasks, cloud tokens, and notification services.

NVD status

Status
Deferred — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
quark / quark drive cpe:2.3:a:quark:quark_drive:<0.8.5:*:*:*:*:*:*:*

References