CVE-2026-81326

Summary

QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password.

Affected Software

VendorProductVersion RangeStatus
QualitySoft CorporationQND Premium0 <= Ver.11.1iaffected
QualitySoft CorporationQND Standard0 <= Ver.11.1iaffected
QualitySoft CorporationQND Advance0 <= Ver.11.0.9iaffected

Weaknesses

  • CWE-321: Use of hard-coded cryptographic key

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References