Home

Description

The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.

PUBLISHED Reserved 2025-02-16 | Published 2025-07-04 | Updated 2025-07-08 | Assigner mitre




CRITICAL: 9.3CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Problem types

CWE-863 Incorrect Authorization

Product status

Default status
unaffected

Any version before 14.0.97
affected

14.1.0 (custom) before 14.1.19
affected

References

support.quest.com/...-sma-agent-vulnerability-cve-2025-26850

cve.org (CVE-2025-26850)

nvd.nist.gov (CVE-2025-26850)

Download JSON