Junglewise Threat Intelligence

CVE-2026-11857: Quanos SCHEMA ST4 local privilege escalation in Client Update Service

CVE-2026-11857 · Severity: info · CVSS 8.4 · Published 2026-06-17

Executive brief

Quanos SCHEMA ST4, a content management system for technical documentation, contains a security flaw in its Client Update Service. A person with existing low-level access to a computer running the software can exploit this flaw to gain full administrative control (SYSTEM privileges) over that machine. This could allow an attacker to bypass security restrictions, access sensitive data, or disrupt operations on the affected workstation. The vendor recommends disabling the update service as a workaround, as no software patch is currently available.

Technical details

A local privilege escalation vulnerability exists in Quanos SCHEMA ST4 on-premises due to insecure deserialization within the .NET Remoting service used by the Client Update Service. The service is configured with TypeFilterLevel.Full and communicates via local named pipes (e.g., 'ST4Updater2'). An authenticated local attacker can connect to the named pipe, identify the .NET Remoting endpoint, and transmit specially crafted serialized objects to achieve arbitrary code execution. Because the update process runs with NT AUTHORITY\SYSTEM privileges, successful exploitation allows a low-privileged user to gain full system control. No patch is available; the vendor recommends disabling the Client Update Service as a mitigation.

Affected products

  • Quanos Solutions GmbH SCHEMA ST4 on-premises All versions; tested version 12.0.4.0 ST4 2022 SP4

Timeline

  • 2025-12-19: disclosed: Initial contact with vendor
  • 2026-01-22: other: Vendor provided workaround to disable service
  • 2026-06-17: advisory: Public disclosure of CVE-2026-11857

References

Related threats