Junglewise Threat Intelligence

CVE-2026-45229: Cp0204 Quark Drive mass assignment in POST /update endpoint

CVE-2026-45229 · Severity: high · CVSS 8.8 · Published 2026-05-13

Executive brief

Quark Drive, an automated cloud storage management tool, contains a security flaw that allows users with basic account access to modify administrative settings. By sending a specially crafted request, an attacker can overwrite the administrator's login credentials, effectively locking out legitimate owners. This allows the attacker to gain full control over the system, including access to sensitive cloud tokens, notification services, and automated tasks.

Technical details

A mass assignment vulnerability (CWE-915) exists in the POST /update endpoint of Quark Drive (quark-auto-save) prior to version 0.8.5. The application used an insufficient deny-list approach for filtering incoming JSON keys in the config_data dictionary. An authenticated attacker can bypass these filters to inject a 'webui' object, allowing them to overwrite stored administrator credentials. Successful exploitation results in a complete takeover of the application, including access to cloud tokens and notification configurations. The vulnerability was remediated in version 0.8.5 by replacing the deny-list with a strict allow-list of permitted configuration keys.

Affected products

  • Cp0204 Quark Drive (quark-auto-save) < 0.8.5

Timeline

  • 2026-04-18: patched: Version 0.8.5 released with fix
  • 2026-05-13: disclosed: Initial vulnerability disclosure
  • 2026-05-13: advisory: NVD publication date

References

Related threats