Skip to content
Threat Feed
high advisory

Missing Authorization Vulnerability in Interprobe Qorela DC

A missing authorization vulnerability (CVE-2026-87748) in Interprobe Qorela DC allows authenticated users to escalate privileges and perform unauthorized actions.

CVE search metadata

CVE search record: CVE-2026-87748. Severity: high. CVSS: 8.8. KEV: no. Product: Qorela DC (1.6.1-RC29 to < 1.6.2). Brief: Missing Authorization Vulnerability in Interprobe Qorela DC. Brief link: https://feed.craftedsignal.io/briefs/2026-09-qorela-dc-auth-bypass/

Interprobe Information Technologies Inc. has disclosed a missing authorization vulnerability, identified as CVE-2026-87748, affecting the Qorela DC platform. The vulnerability exists within versions 1.6.1-RC29 through versions prior to 1.6.2. This flaw allows an authenticated user to bypass existing authorization controls, facilitating unauthorized privilege escalation and system manipulation. As a result, attackers who have established low-privilege access to the Qorela DC interface can leverage this vulnerability to gain broader administrative or functional control, potentially leading to unauthorized system configuration changes or data access. Organizations utilizing Qorela DC are urged to update to version 1.6.2 or later to remediate the vulnerability.

Impact

Successful exploitation of this vulnerability permits authenticated users to perform unauthorized actions beyond their intended scope. This privilege abuse can lead to total loss of integrity and confidentiality within the Qorela DC management interface, depending on the sensitive operations accessible through the bypassed authorization checks.

Recommendation

  • Upgrade all instances of Qorela DC to version 1.6.2 or later to address the authorization flaw documented in CVE-2026-87748.
  • Review access logs for Qorela DC to identify unusual administrative actions or privilege changes originating from low-privileged service or user accounts.
  • Restrict access to the Qorela DC management interface to trusted networks and implement robust authentication controls to minimize the exposure of the application to potentially compromised accounts.

Immediate actions

Upgrade Qorela DC to version 1.6.2 or later.

IT Operations 48h

Mitigations

Upgrade to Qorela DC v1.6.2.

immediate IT Operations

CVE-2026-87748