CVE-2026-45229 Details
Description
Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui object to the config_data dictionary. Attackers can exploit insufficient deny-list filtering to permanently replace stored login credentials, lock out legitimate administrators, and gain persistent access to all configured tasks, cloud tokens, and notification services.
A mass assignment vulnerability has been identified in Quark Drive versions prior to 0.8.5. This vulnerability exists in the POST /update endpoint, where authenticated attackers can overwrite administrator credentials. By posting an arbitrary webui object to the config_data dictionary, attackers exploit inadequate deny-list filtering to permanently replace stored login credentials. This action can lock out legitimate administrators and provide persistent access to all configured tasks, cloud tokens, and notification services.
Users can update to Quark Drive version 0.8.6 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 13, 2026CISA-ADP
Assessed May 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Cp0204/quark-auto-save/commit/ea8377a596446291953dbe36e2d119d85bcd865b | [email protected] | Source CodeVendor |
| https://github.com/Cp0204/quark-auto-save/releases/tag/v0.8.5 | [email protected] | Release NotesVendor |
| https://www.vulncheck.com/advisories/quark-drive-mass-assignment-via-post-update | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-915 | Improperly Controlled Modification of Dynamically-Determined Object Attributes | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Quark Drive | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | New CVE Received | [email protected] |
Volerion