CVE-2025-26850: Critical severity Quest KACE Systems Management Appliance vulnerability
The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26850?
CVE-2025-26850 is categorized as a privilege escalation vulnerability in the Quest KACE Systems Management Appliance.
How do I fix CVE-2025-26850?
To fix CVE-2025-26850, upgrade the Quest KACE Systems Management Appliance to version 14.0.97 or 14.1.19 and above.
Which versions of Quest KACE Systems Management Appliance are affected by CVE-2025-26850?
Versions of Quest KACE Systems Management Appliance prior to 14.0.97 and between 14.1.0 and 14.1.18 are affected by CVE-2025-26850.
What systems are impacted by CVE-2025-26850?
CVE-2025-26850 affects managed systems using the vulnerable versions of the Quest KACE Systems Management Appliance agent.
Is CVE-2025-26850 being actively exploited?
As of now, there is no public indication that CVE-2025-26850 is being actively exploited, but it is advisable to apply the patch immediately.