PT-2026-26633 · Qhora · Qhora

CVE-2025-62843

·

Published

2026-03-20

·

Updated

2026-03-30

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QHora versions prior to 2.6.3.009
Description An issue exists in QHora where an improper restriction of communication channels to intended endpoints can allow an attacker with physical access to gain elevated privileges. The issue was exploited as part of the Pwn2Own Ireland competition, resulting in root access when chained with other flaws.
Recommendations Update to QHora version 2.6.3.009 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62843
ZDI-26-237

Affected Products

Qhora