AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-13040

HIGH · CVSS 8.8 EPSS 0.47%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-12-31 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 8.8. It may be remotely exploitable.

CVE
CVE-2024-13040
Severity
HIGH
CVSS
8.8
EPSS
0.47%

Original NVD Description

The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key vulnerability. By controlling the user ID parameter, remote attackers with regular privileges could access certain features as any user, modify any user's account information and privileges, leading to privilege escalation.