Improper Access Control in QND by QualitySoft
CVE-2026-84408

8.7HIGH

What is CVE-2026-84408?

QND by QualitySoft is impacted by an improper access control vulnerability related to its named pipe. This flaw could allow a local attacker, already authenticated on a Windows PC with the QND client installed, to execute arbitrary commands with elevated SYSTEM privileges. Such exploitation can lead to unauthorized access and control over sensitive system operations, emphasizing the need for immediate remediation to protect affected systems.

Affected Version(s)

QND Advance 0

QND Premium 0

QND Standard 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

CVSS V3.0

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.