CVE-2026-67244
Last modified
CVE-2026-67244 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through an unsafe format string operation. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through an unsafe format string operation. An authenticated administrator can exploit this issue to disclose memory information or cause denial of service of the affected component. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Asustor | Data Master | >= 4.1.0.rhu2, <= 4.3.3.run1 |
| Asustor | Data Master | >= 5.0.0.ra82, < 5.1.4.rjv2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-67244?
How severe is CVE-2026-67244?
How do I fix CVE-2026-67244?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-67238RabbitMQ is a messaging and streaming broker. Prior to versi…7.1
- CVE-2026-67239RabbitMQ is a messaging and streaming broker. From 3.13.0 un…7.6
- CVE-2026-67240RabbitMQ is a messaging and streaming broker. Prior to versi…2.3
- CVE-2026-67241RabbitMQ is a messaging and streaming broker. From 4.2.0 unt…4.8
- CVE-2026-67242RabbitMQ is a messaging and streaming broker. From 4.2.0 unt…6.3
- CVE-2026-67243freo2 provided by refirio contains an unrestricted upload of…8.6
- CVE-2026-67245A path traversal vulnerability was found in the VPN Clients …8.1
- CVE-2026-67246A path traversal vulnerability was found in the Wallpaper co…6.5
- CVE-2026-67247A path traversal vulnerability was found in the IHM Log hand…6.5
- CVE-2026-67248A stack-based buffer overflow vulnerability was found in the…8.8
- CVE-2026-6725The WPC Smart Messages for WooCommerce plugin for WordPress …6.4
- CVE-2026-6726An information leakage vulnerability was reported in the TCG…7.9
Are you affected by CVE-2026-67244?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
