Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 14 May 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cp0204
Cp0204 quark-auto-save |
|
| Vendors & Products |
Cp0204
Cp0204 quark-auto-save |
Wed, 13 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated attackers to overwrite administrator credentials by posting an arbitrary webui object to the config_data dictionary. Attackers can exploit insufficient deny-list filtering to permanently replace stored login credentials, lock out legitimate administrators, and gain persistent access to all configured tasks, cloud tokens, and notification services. | |
| Title | Quark Drive < 0.8.5 Mass Assignment via POST /update | |
| Weaknesses | CWE-915 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-14T19:52:24.774Z
Reserved: 2026-05-11T14:14:49.611Z
Link: CVE-2026-45229
Updated: 2026-05-14T16:19:14.919Z
Status : Deferred
Published: 2026-05-13T21:16:49.733
Modified: 2026-05-14T16:24:56.240
Link: CVE-2026-45229
No data.
OpenCVE Enrichment
Updated: 2026-05-14T14:33:34Z