Junglewise Threat Intelligence

CVE-2026-81326: QualitySoft QND hard-coded cryptographic key

CVE-2026-81326 · Severity: medium · CVSS 5.5 · Published 2026-09-16

Executive brief

QND is a Windows client application used for administrative management. A local attacker with standard user login credentials can extract embedded administrator credentials (ID and password) from the system due to a hard-coded cryptographic key, potentially leading to unauthorized administrative access and control of the affected PC.

Technical details

The vulnerability is a use of hard-coded cryptographic key (CWE-321) in QND's Windows client component. An attacker with local access and standard user privileges can retrieve the hard-coded key and use it to decrypt stored administrator credentials. The attack requires local login to the Windows PC where the QND client is installed and standard user-level access; no special network connectivity or privilege escalation is needed for the credential theft itself. A successful exploit allows the attacker to obtain the administrator ID and password, enabling full administrative control. Patches have been released by QualitySoft Corporation for affected versions.

Affected products

  • QualitySoft Corporation QND Premium Ver. 11.1i and earlier
  • QualitySoft Corporation QND Standard Ver. 11.1i and earlier
  • QualitySoft Corporation QND Advance Ver. 11.0.9i and earlier

Timeline

  • 2026-09-16: disclosed

References