Description
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.
Published: 2026-07-27
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker who knows valid credentials or API keys to access the Quest KACE Systems Deployment Appliance via its API endpoints, even when IP-based restrictions are applied to the web console. This lack of authorization on the API surface means an attacker can gain the same level of control as a legitimate administrator, potentially exposing or altering all configuration settings and data. The weakness is a classic case of improper authorization.

Affected Systems

Quest KACE Systems Deployment Appliance version 11.0.273 is affected. No other versions are listed in the official CNA data.

Risk and Exploitability

Because the API is reachable from any network location, an attacker only needs network access to the appliance and valid credentials. The EPSS score is <1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed public exploitation yet. However, once credentials are compromised, exploitation is straightforward and could lead to a complete takeover of the managed environment. The CVSS score is 9.8, but the potential impact warrants high risk from a security perspective.

Generated by OpenCVE AI on August 5, 2026 at 01:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for Quest KACE Systems Deployment Appliance
  • If an immediate patch is unavailable, restrict API traffic to trusted IP ranges or disable unused API endpoints via the appliance configuration
  • Rotate or regenerate any API keys and enforce strong, unique credentials for all administrative accounts

Generated by OpenCVE AI on August 5, 2026 at 01:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title API Authorization Bypass Enabling Full Deployment Compromise in Quest KACE SMA 11.0.273

Wed, 05 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title API Endpoints Unrestricted Despite IP Whitelisting in Quest KACE SMA
Weaknesses CWE-285

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title API Endpoints Unrestricted Despite IP Whitelisting in Quest KACE SMA
Weaknesses CWE-284
CWE-285
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Quest
Quest kace Systems Deployment Appliance
Vendors & Products Quest
Quest kace Systems Deployment Appliance

Mon, 27 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.
References

Subscriptions

Quest Kace Systems Deployment Appliance Kace Systems Management Appliance
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-28T14:55:09.026Z

Reserved: 2021-05-06T00:00:00.000Z

Link: CVE-2021-32084

cve-icon Vulnrichment

Updated: 2026-07-28T14:37:40.251Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-27T22:16:56.543

Modified: 2026-08-03T14:31:11.327

Link: CVE-2021-32084

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:45:04Z

Weaknesses