Junglewise Threat Intelligence

CVE-2021-32084: Quest KACE SMA access control bypass in API endpoints

CVE-2021-32084 · Severity: info · CVSS 0 · Published 2026-07-27

Technologies: Quest KACE Systems Management Appliance, Quest KACE Systems Management Appliance (SMA). Vendors: Quest.

Executive brief

Quest KACE Systems Management Appliance (SMA) contains a security flaw where network access restrictions applied to the web management console do not apply to the application's API. If an attacker obtains valid credentials or API keys, they can bypass IP-based access controls to manage the appliance remotely. This could lead to a full compromise of the KACE environment, potentially allowing unauthorized changes to managed systems across the organization.

Technical details

An access control bypass vulnerability exists in Quest KACE Systems Management Appliance (SMA) version 11.0.273. While the appliance allows administrators to restrict web console access to specific IP addresses or subnets, these restrictions are not enforced on API endpoints. An attacker with valid credentials or API keys can interact with the API from any network location, bypassing intended perimeter or host-based access controls. This allows for unauthorized administrative actions and potential environment-wide compromise. The issue is resolved in KACE SMA version 11.1.

Affected products

  • Quest KACE Systems Management Appliance (SMA) 11.0.273

Timeline

  • 2021-07-01: disclosed: Initial internal KB article creation date
  • 2026-07-27: advisory: NVD publication date
  • 2021-07-01: patched: Resolved in version 11.1

References

Related threats