CVE-2026-90503 Details
Description
A flaw has been found in Chengdu Qilu Technology Ludashi 6.1026.4715.714. The affected element is the function sub_11008 in the library ComputerZ_x64.sys. Executing a manipulation of the argument PhysicalAddress can lead to information disclosure. The attack needs to be launched locally. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
An information disclosure vulnerability has been identified in Chengdu Qilu Technology Ludashi version 6.1026.4715.714. The issue arises in the function sub_11008 of the library ComputerZ_x64.sys, where improper handling of the PhysicalAddress argument can be exploited to leak sensitive information. This vulnerability requires local access to the affected system to be exploited.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 13, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/cve/CVE-2026-90503 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/895249 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403091 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403091/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Chengdu Qilu Technology Ludashi | 6.1026.4715.714 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 13, 2026 | New CVE Received | [email protected] |
Volerion