Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-18265: OSNEXUS QuantaStor allows unauthenticated remote code execution
CVE-2026-18265 · published 1 month ago
Summary
The OSNEXUS QuantaStor storage system can be accessed without a login, letting an outside attacker run any program on the server with full administrator rights. This could let the attacker take control of the system or steal data. Apply the vendor's security update and limit network access to the system until it is patched.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| osnexus | quantastor | 6.7.3.010+9c965a6414 |
Original advisory text
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the configuration of Kapacitor. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-30036.
The specific flaw exists within the configuration of Kapacitor. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-30036.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published20 Aug 2026
Updated3 Oct 2026
First seen20 Aug 2026
Track software like this
Free during beta