CVE-2026-81326: Medium severity QND vulnerability
Published Sep 16, 2026
·Updated
QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password.
Affected Software
1 affected component
QND
Event History
Sep 16, 2026
CVE Published
via MITRE·07:29 AM
Data Sourced
via MITRE·07:29 AM
DescriptionSeverity
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be locally logged in to a Windows PC with the affected QND client installed. The published vector also indicates low privileges are required and no user interaction is needed.
2
What could an attacker obtain?
The issue may allow the local attacker to obtain administrator credentials, including an ID and password.
3
How can I determine whether a system is exposed?
Check whether the QND client is installed on a Windows PC. The provided information does not identify affected versions or configuration-specific conditions.