Junglewise Threat Intelligence

CVE-2026-84408: QND improper access control in named pipe

CVE-2026-84408 · Severity: high · CVSS 8.8 · Published 2026-09-16

Executive brief

QND is a Windows client application used for secure network communication and credential management. A local user logged into a Windows PC with QND installed can exploit an improperly protected named pipe to execute arbitrary commands with SYSTEM-level privileges, effectively gaining full administrative control of the machine.

Technical details

CVE-2026-84408 is an improper access control vulnerability (CWE-782) in a Windows named pipe used by QND. A local attacker with user-level login access can leverage this to execute arbitrary commands with SYSTEM privileges. The vulnerability requires only local access and no additional authentication; patches are available through the vendor's customer portal.

Affected products

  • QualitySoft QND Premium 11.1i and earlier
  • QualitySoft QND Standard 11.1i and earlier
  • QualitySoft QND Advance 11.0.9i and earlier

Timeline

  • 2026-09-16: disclosed

References