PT-2026-40801 · Unknown · Quark Drive

Katriel Moses

·

Published

2026-05-13

·

Updated

2026-05-14

·

CVE-2026-45229

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Quark Drive versions prior to 0.8.5
Description A mass assignment issue exists in the "POST /update" endpoint. Authenticated attackers can overwrite administrator credentials by submitting an arbitrary webui object to the config data dictionary. This is possible due to insufficient deny-list filtering, which allows the permanent replacement of stored login credentials. Consequently, legitimate administrators may be locked out, and attackers can gain persistent access to all configured tasks, cloud tokens, and notification services.
Recommendations Update to version 0.8.5 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-45229

Affected Products

Quark Drive