Junglewise Threat Intelligence

CVE-2026-18265: OSNEXUS QuantaStor missing authentication remote code execution in Kapacitor

CVE-2026-18265 · Severity: critical · CVSS 9.8 · Published 2026-08-20

Executive brief

OSNEXUS QuantaStor is a storage management platform used to administer enterprise storage systems. A misconfiguration in the bundled Kapacitor monitoring component allows unauthenticated remote attackers to execute arbitrary code with root privileges, potentially compromising the entire storage infrastructure and any data stored within it.

Technical details

The vulnerability is a missing authentication flaw in the Kapacitor configuration within OSNEXUS QuantaStor. An attacker can remotely access the Kapacitor functionality without providing credentials due to improper access controls. The vulnerability is network-reachable and requires no authentication or user interaction. Successful exploitation allows arbitrary code execution in the root security context. The vulnerability affects QuantaStor versions prior to 6.8.0, which includes a fix. This was reported as ZDI-CAN-30036 and publicly disclosed on July 29, 2026.

Affected products

  • OSNEXUS QuantaStor prior to 6.8.0

Timeline

  • 2026-06-10: disclosed: Vulnerability reported to vendor
  • 2026-07-29: patched: Fixed in QuantaStor 6.8.0; coordinated public release
  • 2026-07-29: advisory: ZDI-26-480 / ZDI-CAN-30036 advisory published

References