CVE-2026-90508 Details
Description
A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been identified in Chengdu Qilu Technology Ludashi version 6.1026.4715.714. The issue resides in the Message Dispatch Handler component, specifically within the ProtectFilter64.sys library. The vulnerability arises from the MessageNotifyCallback function, where a manipulation can lead to missing authorization. This flaw requires local exploitation. A proof-of-concept for this vulnerability has been made public.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 13, 2026CISA-ADP
Assessed Sep 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/lzty/fc5f336dca4c287ab4c22168b6dc8ec2 | [email protected] | Exploit |
| https://vuldb.com/cve/CVE-2026-90508 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/895271 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403096 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403096/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Chengdu Qilu Technology Ludashi | 6.1026.4715.714 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | CISA-ADP |
| Sep 13, 2026 | New CVE Received | [email protected] |
Volerion