CVE-2026-84408

Summary

QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to execute arbitrary commands with SYSTEM privileges.

Affected Software

VendorProductVersion RangeStatus
QualitySoft CorporationQND Premium0 <= Ver.11.1iaffected
QualitySoft CorporationQND Standard0 <= Ver.11.1iaffected
QualitySoft CorporationQND Advance0 <= Ver.11.0.9iaffected

Weaknesses

  • CWE-782: Exposed IOCTL with insufficient access control

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References