PT-2026-46296 · Osnexus · Quantastor

·

CVE-2026-10880

·

Published

2026-06-04

·

Updated

2026-06-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OSNexus QuantaStor versions prior to 6.6.2
Description An unauthenticated remote attacker can perform a blind SQL injection via the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, which allows the attacker to bypass authentication and log in as an administrator without a valid password. Additionally, attackers can recover stored password hashes one character at a time by analyzing differing login error responses.
Recommendations Update to version 6.6.2 or later. As a temporary workaround, restrict access to the login endpoint to trusted IP addresses to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10880

Affected Products

Quantastor