CVE-2024-27123: QcalAgent
Published Sep 18, 2026
·Updated
A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vulnerability to bypass security mechanisms or read application data.
We have already fixed the vulnerability in the following version: QcalAgent 1.1.9 and later
Affected Software
1 affected component
QcalAgent<1.1.9
Event History
Sep 18, 2026
CVE Published
via MITRE·06:49 AM
Data Sourced
via MITRE·06:49 AM
RemedyDescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is described as exploitable by local attackers. An attacker would need local access to the affected QcalAgent environment.
2
Which versions are affected?
The vulnerability is fixed in QcalAgent 1.1.9 and later. Versions earlier than 1.1.9 should be treated as affected based on the available information.
3
What can exploitation allow?
Successful exploitation may allow a local attacker to bypass security mechanisms or read application data.