LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-45229

CVE-2026-45229 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: May 14, 2026

Quark Drive - Broken Access Control

Published: May 13, 2026Updated: May 14, 2026Remote Exploitable

Overview

Quark Drive < 0.8.5 contains a broken access control vulnerability caused by insufficient deny-list filtering in the POST /update endpoint, letting authenticated attackers overwrite administrator credentials and gain persistent access.

Severity & Score

Severity: High
CVSS Score: 8.8

Impact

Authenticated attackers can overwrite admin credentials, lock out legitimate users, and gain persistent full access to tasks, tokens, and notifications.

Mitigation

Update to version 0.8.5 or later.

Details

CVE ID
CVE-2026-45229
Severity
High
CVSS Score
8.8
Type
broken_access_control
Status
rejected

CWE

  • CWE-915

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H