<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Qorela DC (1.6.1-RC29 to &lt; 1.6.2) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/qorela-dc-1.6.1-rc29-to--1.6.2/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 12:27:11 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/qorela-dc-1.6.1-rc29-to--1.6.2/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Missing Authorization Vulnerability in Interprobe Qorela DC</title><link>https://feed.craftedsignal.io/briefs/2026-09-qorela-dc-auth-bypass/</link><pubDate>Tue, 29 Sep 2026 12:27:11 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-qorela-dc-auth-bypass/</guid><description>A missing authorization vulnerability (CVE-2026-87748) in Interprobe Qorela DC allows authenticated users to escalate privileges and perform unauthorized actions.</description><content:encoded><![CDATA[<p>Interprobe Information Technologies Inc. has disclosed a missing authorization vulnerability, identified as CVE-2026-87748, affecting the Qorela DC platform. The vulnerability exists within versions 1.6.1-RC29 through versions prior to 1.6.2. This flaw allows an authenticated user to bypass existing authorization controls, facilitating unauthorized privilege escalation and system manipulation. As a result, attackers who have established low-privilege access to the Qorela DC interface can leverage this vulnerability to gain broader administrative or functional control, potentially leading to unauthorized system configuration changes or data access. Organizations utilizing Qorela DC are urged to update to version 1.6.2 or later to remediate the vulnerability.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability permits authenticated users to perform unauthorized actions beyond their intended scope. This privilege abuse can lead to total loss of integrity and confidentiality within the Qorela DC management interface, depending on the sensitive operations accessible through the bypassed authorization checks.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of Qorela DC to version 1.6.2 or later to address the authorization flaw documented in CVE-2026-87748.</li>
<li>Review access logs for Qorela DC to identify unusual administrative actions or privilege changes originating from low-privileged service or user accounts.</li>
<li>Restrict access to the Qorela DC management interface to trusted networks and implement robust authentication controls to minimize the exposure of the application to potentially compromised accounts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>