Description
OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the configuration of Kapacitor. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-30036.
Published: 2026-08-20
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OSNEXUS QuantaStor is affected by a missing authentication flaw in its Kapacitor configuration that permits remote attackers to run arbitrary code with root privileges. The weakness allows an attacker to bypass all authentication checks and immediately execute commands on the underlying system, potentially compromising confidentiality, integrity, and availability of the host and any services running on it.

Affected Systems

This vulnerability applies to installations of OSNEXUS QuantaStor. No specific affected product versions are listed in the current advisory, so all deployed instances of QuantaStor are potentially vulnerable until a patch is applied or other mitigations are enforced.

Risk and Exploitability

The risk is high, reflected by a CVSS score of 9.8. The EPSS score indicates a 1% probability of exploitation, and the vulnerability is not currently listed in CISA’s KEV catalog. The attack vector is purely remote and requires no authentication; once access is achieved, an attacker can execute code as root. Based on the lack of authentication controls and the severity rating, the likelihood of exploitation remains significant in environments where the vulnerable interfaces are exposed to untrusted networks.

Generated by OpenCVE AI on August 21, 2026 at 14:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official OSNEXUS QuantaStor security patch or upgrade to the latest release that fixes the missing authentication flaw.
  • Restrict network access to the Kapacitor configuration interface using firewall rules or network segmentation so that only trusted hosts can reach it.
  • If a patch is not immediately available, disable the Kapacitor service or remove it from the exposed interface until authentication can be enforced.

Generated by OpenCVE AI on August 21, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Osnexus
Osnexus quantastor
Vendors & Products Osnexus
Osnexus quantastor

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of OSNEXUS QuantaStor. Authentication is not required to exploit this vulnerability. The specific flaw exists within the configuration of Kapacitor. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-30036.
Title OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability
Weaknesses CWE-306
References
Metrics cvssV3_0

{'score': 9.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Osnexus Quantastor
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-08-26T19:50:02.042Z

Reserved: 2026-07-29T17:00:40.040Z

Link: CVE-2026-18265

cve-icon Vulnrichment

Updated: 2026-08-26T19:49:55.931Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T17:17:23.017

Modified: 2026-09-01T20:57:57.143

Link: CVE-2026-18265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T14:45:16Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function