CVE-2026-84408: High severity QND QND client vulnerability
Published Sep 16, 2026
·Updated
QND contains an improper access control vulnerability in a named pipe, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to execute arbitrary commands with SYSTEM privileges.
Affected Software
1 affected component
QND QND client
Event History
Sep 16, 2026
CVE Published
via MITRE·07:30 AM
Data Sourced
via MITRE·07:30 AM
DescriptionSeverity
Frequently Asked Questions
1
Who is exposed to this vulnerability?
Windows PCs where the QND client is installed are exposed. Exploitation requires an attacker to already be logged in locally with low privileges.
2
What level of access can an attacker gain?
A successful attacker may execute arbitrary commands with SYSTEM privileges, giving them full control of the affected Windows PC.
3
Is this remotely exploitable without prior access?
The provided information identifies the attacker as local and logged in to the affected Windows PC. It does not indicate that unauthenticated remote exploitation is possible.