{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/qorela-dc-1.6.1-rc29-to--1.6.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:interprobe:qorela_dc:1.6.1-rc29:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-87748"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Qorela DC (1.6.1-RC29 to \u003c 1.6.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Interprobe Information Technologies"],"content_html":"\u003cp\u003eInterprobe Information Technologies Inc. has disclosed a missing authorization vulnerability, identified as CVE-2026-87748, affecting the Qorela DC platform. The vulnerability exists within versions 1.6.1-RC29 through versions prior to 1.6.2. This flaw allows an authenticated user to bypass existing authorization controls, facilitating unauthorized privilege escalation and system manipulation. As a result, attackers who have established low-privilege access to the Qorela DC interface can leverage this vulnerability to gain broader administrative or functional control, potentially leading to unauthorized system configuration changes or data access. Organizations utilizing Qorela DC are urged to update to version 1.6.2 or later to remediate the vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability permits authenticated users to perform unauthorized actions beyond their intended scope. This privilege abuse can lead to total loss of integrity and confidentiality within the Qorela DC management interface, depending on the sensitive operations accessible through the bypassed authorization checks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Qorela DC to version 1.6.2 or later to address the authorization flaw documented in CVE-2026-87748.\u003c/li\u003e\n\u003cli\u003eReview access logs for Qorela DC to identify unusual administrative actions or privilege changes originating from low-privileged service or user accounts.\u003c/li\u003e\n\u003cli\u003eRestrict access to the Qorela DC management interface to trusted networks and implement robust authentication controls to minimize the exposure of the application to potentially compromised accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T12:27:11Z","date_published":"2026-09-29T12:27:11Z","id":"https://feed.craftedsignal.io/briefs/2026-09-qorela-dc-auth-bypass/","summary":"A missing authorization vulnerability (CVE-2026-87748) in Interprobe Qorela DC allows authenticated users to escalate privileges and perform unauthorized actions.","title":"Missing Authorization Vulnerability in Interprobe Qorela DC","url":"https://feed.craftedsignal.io/briefs/2026-09-qorela-dc-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Qorela DC (1.6.1-RC29 to \u003c 1.6.2)","version":"https://jsonfeed.org/version/1.1"}