CVE-2026-30896: High severity Qsee Qsee Client vulnerability
The installer for Qsee Client versions 1.0.1 and prior insecurely load Dynamic Link Libraries (DLLs). When a user is directed to place some malicious DLL to the same directory and execute the affected installer, then arbitrary code may be executed with the administrative privilege.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-30896?
CVE-2026-30896 is considered a critical vulnerability due to its exploitation potential allowing arbitrary code execution with administrative privileges.
How do I fix CVE-2026-30896?
To fix CVE-2026-30896, update to a version of Qsee Client newer than 1.0.1 that mitigates the DLL loading vulnerability.
What platforms are affected by CVE-2026-30896?
CVE-2026-30896 affects Qsee Client installations on Windows platforms.
What types of attacks can exploit CVE-2026-30896?
CVE-2026-30896 can be exploited through the placement of a malicious DLL in the installation directory which, when executed, allows attacker-controlled code to run.
Is there a known workaround for CVE-2026-30896?
A recommended workaround for CVE-2026-30896 is to ensure that untrusted users do not have write access to the Qsee Client installation directory.