Missing Authorization Vulnerability in Interprobe Qorela DC
A missing authorization vulnerability (CVE-2026-87748) in Interprobe Qorela DC allows authenticated users to escalate privileges and perform unauthorized actions.
CVE search metadata
CVE search record: CVE-2026-87748. Severity: high. CVSS: 8.8. KEV: no. Product: Qorela DC (1.6.1-RC29 to < 1.6.2). Brief: Missing Authorization Vulnerability in Interprobe Qorela DC. Brief link: https://feed.craftedsignal.io/briefs/2026-09-qorela-dc-auth-bypass/
Interprobe Information Technologies Inc. has disclosed a missing authorization vulnerability, identified as CVE-2026-87748, affecting the Qorela DC platform. The vulnerability exists within versions 1.6.1-RC29 through versions prior to 1.6.2. This flaw allows an authenticated user to bypass existing authorization controls, facilitating unauthorized privilege escalation and system manipulation. As a result, attackers who have established low-privilege access to the Qorela DC interface can leverage this vulnerability to gain broader administrative or functional control, potentially leading to unauthorized system configuration changes or data access. Organizations utilizing Qorela DC are urged to update to version 1.6.2 or later to remediate the vulnerability.
Impact
Successful exploitation of this vulnerability permits authenticated users to perform unauthorized actions beyond their intended scope. This privilege abuse can lead to total loss of integrity and confidentiality within the Qorela DC management interface, depending on the sensitive operations accessible through the bypassed authorization checks.
Recommendation
- Upgrade all instances of Qorela DC to version 1.6.2 or later to address the authorization flaw documented in CVE-2026-87748.
- Review access logs for Qorela DC to identify unusual administrative actions or privilege changes originating from low-privileged service or user accounts.
- Restrict access to the Qorela DC management interface to trusted networks and implement robust authentication controls to minimize the exposure of the application to potentially compromised accounts.
Immediate actions
Upgrade Qorela DC to version 1.6.2 or later.
Mitigations
Upgrade to Qorela DC v1.6.2.
CVE-2026-87748