Sceawere
Vulnerability Detail
CVE-2026-87748UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Qorela DC Privilege Abuse Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 13h ago
- Vendor
- Interprobe Information Technologies Inc.
- Product
- Qorela DC
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Missing Authorization vulnerability in Interprobe Information Technologies Inc. Qorela DC allows Privilege Abuse. This issue affects Qorela DC: from 1.6.1-RC29 before v1.6.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-29T12:17:12.527Z",
"pubdate": "2026-09-29T12:17:12.527Z",
"executiveSummary": "A critical Missing Authorization vulnerability exists within Interprobe Information Technologies Inc. Qorela DC, impacting versions 1.6.1-RC29 through pre-v1.6.2 releases.\nThis vulnerability allows an unauthorized actor to perform unauthorized actions by bypassing intended access control mechanisms, leading to potential privilege abuse.\nThe flaw stems from insufficient validation of authorization tokens or lack of access checks on sensitive endpoints, enabling attackers to elevate their functional permissions beyond their assigned scope.\nThe impact includes unauthorized modification of system configurations, access to restricted data, or the ability to execute administrative commands without legitimate credentials.\nThe vulnerability poses a severe risk to the integrity and confidentiality of the Qorela DC environment, as it grants attackers the ability to manipulate system states under the guise of higher-privileged entities.\nExploitation requires network connectivity to the affected Qorela DC instance but does not necessarily mandate advanced authentication, depending on the specific endpoint being targeted by the missing authorization check.",
"technicalDetails": "The vulnerability is characterized as an Improper Authorization flaw, specifically categorized under the failure of the application to verify that the requesting user possesses the requisite permissions for a specific operation or resource access.\nIn Qorela DC, the root cause involves the omission of robust access control checks within the application's request-handling logic. When a user interacts with the system, the application processes the request without correctly validating the authorization context, assuming the validity of the request based on parameters that can be manipulated by an attacker.\nThe attack flow commences with an attacker identifying a restricted administrative or privileged function exposed by the Qorela DC API or web interface. By intercepting and analyzing traffic, the attacker observes that sensitive actions do not perform server-side validation of the user's role or access rights.\nThe attacker may then craft a malicious HTTP request directed at these vulnerable endpoints. Because the application fails to verify the session or the authorization header against the requested resource, the server proceeds to execute the action as if the request originated from an authorized administrator.\nThis privilege abuse scenario allows for unauthorized state changes. For instance, if an endpoint responsible for user management or system configuration lacks authorization checks, an attacker could add new administrative users, modify security policies, or access sensitive telemetry data processed by the platform.\nThe affected versions are confirmed as 1.6.1-RC29 and any subsequent releases prior to v1.6.2. The vulnerability exists within the application's backend controller or middleware components that are responsible for securing administrative endpoints.\nPost-exploitation, the attacker achieves persistence or total system control. The lack of proper authorization acts as a gateway, allowing the attacker to bypass the security perimeter entirely without needing to compromise legitimate credentials. This effectively grants the attacker the same authority as the highest-privileged user configured in the Qorela DC architecture, facilitating full control over the monitored network flows or system management tasks provided by the solution."
}