CVE-2026-84408 Details
Description
QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to execute arbitrary commands with SYSTEM privileges.
An improper access control vulnerability has been identified in the QND Windows client, specifically in the named pipe mechanism. This vulnerability allows a local attacker, logged into a Windows PC with the affected QND client version, to execute arbitrary commands with SYSTEM privileges. The issue affects multiple QND products, including QND Premium, QND Standard, and QND Advance, all through version 11.1i or earlier, except for QND Advance which is through version 11.0.9i.
Users are advised to update to QND version 11.0.9i or 11.1i, depending on their current version, and to apply the available patch. Instructions for downloading the patch can be found on the QualitySoft product vulnerabilities 2026 webpage.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN95825631/ | [email protected] | AdvisoryBundleRemedy |
| https://www.qualitysoft.com/product/qnd_vulnerabilities_2026/ | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-782 | Exposed IOCTL with Insufficient Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| QualitySoft QND Premium | <= 11.1i |
CPE
Remediation
| |
| QualitySoft QND Standard | <= 11.1i |
CPE
Remediation
| |
| QualitySoft QND Advance | <= 11.0.9i |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion