CVE-2026-18265: OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the configuration of Kapacitor. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-30036.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-CAN-30036 - Compensating control
Mitigate CVE/issue by adding compensating network access control so the QuantaStor/Kapacitor functionality that lacks authentication is not reachable from untrusted networks (e.g., restrict inbound access to trusted IPs via firewall/ACL).
Event History
Frequently Asked Questions
Does an attacker need valid credentials or user interaction to exploit this issue?
No. The vulnerability can be exploited without authentication and does not require user interaction.
What level of access could a successful attacker obtain?
An attacker can execute arbitrary code in the context of root, giving them full control over the affected system.
Which component is involved in the vulnerable configuration?
The flaw exists in the configuration of Kapacitor on affected OSNEXUS QuantaStor installations.