CVE-2026-45229 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: May 14, 2026
Quark Drive - Broken Access Control
Published: May 13, 2026Updated: May 14, 2026Remote Exploitable
Overview
Quark Drive < 0.8.5 contains a broken access control vulnerability caused by insufficient deny-list filtering in the POST /update endpoint, letting authenticated attackers overwrite administrator credentials and gain persistent access.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Authenticated attackers can overwrite admin credentials, lock out legitimate users, and gain persistent full access to tasks, tokens, and notifications.
Mitigation
Update to version 0.8.5 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-45229
- Severity
- High
- CVSS Score
- 8.8
- Type
- broken_access_control
- Status
- rejected
CWE
- CWE-915
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H