CVE-2026-10880
EUVD-2026-3430504.06.2026, 18:16
OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to bypass authentication and log in as an administrator without supplying a valid password.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| osnexus | quantastor | 5.9 ≤ 𝑥 < 6.6.1 | CNA |