CVE-2026-30896
Last modified
CVE-2026-30896 is a high-severity vulnerability rated 8.4/10 on the CVSS scale. The installer for Qsee Client versions 1.0.1 and prior insecurely load Dynamic Link Libraries (DLLs). When a user is directed to place some malicious DLL to the same directory and execute the affected installer, then arbitrary code may be executed with the administrative privilege.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
The installer for Qsee Client versions 1.0.1 and prior insecurely load Dynamic Link Libraries (DLLs). When a user is directed to place some malicious DLL to the same directory and execute the affected installer, then arbitrary code may be executed with the administrative privilege.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Q-See | Qsee Client | <= 1.0.1 |
References
- https://jvn.jp/en/jp/JVN11676807/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-30896?
How severe is CVE-2026-30896?
How do I fix CVE-2026-30896?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-30890Combodo iTop is a web based IT service management tool. Prio…8
- CVE-2026-30891Discourse is an open-source discussion platform. Prior to ve…6.5
- CVE-2026-30892crun is an open source OCI Container Runtime fully written i…7.8
- CVE-2026-30893Wazuh is a free and open source platform used for threat pre…9.9
- CVE-2026-30894Lack of output escaping leads to a XSS vector in the content…6.1
- CVE-2026-30895Lack of output escaping leads to a XSS vector in the readmor…6.1
- CVE-2026-30897A stack-based buffer overflow vulnerability in Fortinet Fort…6.6
- CVE-2026-30898An example of BashOperator in Airflow documentation suggeste…8.8
- CVE-2026-3090The Post SMTP – Complete Email Deliverability and SMTP Solut…7.2
- CVE-2026-30900Improper Check of minimum version in update functionality of…7.8
- CVE-2026-30901Improper Input Validation in Zoom Rooms for Windows before 6…7.8
- CVE-2026-30902Improper Privilege Management in certain Zoom Clients for Wi…7.8
Are you affected by CVE-2026-30896?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
