AUGUST 17, 2026
Live Feed
Back to database
Case File

CVE-2026-10880

CRITICAL · CVSS 9.8 EPSS 0.44%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-06-04 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It may be remotely exploitable. It involves a SQL injection risk.

CVE
CVE-2026-10880
Severity
CRITICAL
CVSS
9.8
EPSS
0.44%

Original NVD Description

OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to bypass authentication and log in as an administrator without supplying a valid password.