CVE-2026-81326 Details
Description
QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password.
A vulnerability exists in the QND Windows client, specifically in the Premium, Standard, and Advance versions through 11.1i, that involves the use of a hard-coded cryptographic key. This flaw may enable a local attacker, logged into a Windows PC with the affected QND client version, to retrieve administrator credentials, including the ID and password.
Users are advised to update to QND Version 11.0.9i or 11.1i and apply the available patch. Instructions for accessing the patch can be found on the QualitySoft QND Vulnerabilities 2026 webpage.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN95825631/ | [email protected] | AdvisoryBundleRemedy |
| https://www.qualitysoft.com/product/qnd_vulnerabilities_2026/ | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-321 | Use of Hard-coded Cryptographic Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| QualitySoft QND Premium | <= 11.1i |
CPE
Remediation
| |
| QualitySoft QND Standard | <= 11.1i |
CPE
Remediation
| |
| QualitySoft QND Advance | <= 11.0.9i |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion