CVE-2026-15476
A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbck
CVSS
5.3
Medium
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Published: Jul 12, 2026 · Last modified: Jul 13, 2026 · CWE-266 · CWE-284
0.1%EPSS · 30 days0.1%
2026-08-062026-09-02
A security vulnerability has been detected in QILING Disk Master 6.0.0.0. The impacted element is an unknown function in the library diskbckp.sys of the component Kernel Driver. Such manipulation leads to improper access controls. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. It is suggested to upgrade the affected component.
- vuldb.comhttps://vuldb.com/cve/CVE-2026-15476
- vuldb.comhttps://vuldb.com/submit/835610
- vuldb.comhttps://vuldb.com/vuln/377781
- vuldb.comhttps://vuldb.com/vuln/377781/cti
- winslow1984.comhttps://winslow1984.com/books/cve-collection/page/qiling-disk-master-kernel-driver-diskbckpsys-6-0-0-0-local-privilege-escalation
- www.idiskhome.comhttps://www.idiskhome.com/download/beta/multi_DiskMaster_Pro_Trial.exe
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-854016.3 MED—
———A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 23.0.4 can resolve this issue. This patch is called ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec. It is suggested to upgrade the affected component.6hCVE-2026-851477.5 HIG—
———SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for communication.6hCVE-2026-852416.3 MED—
———A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the component Graph Write Endpoint. Executing a manipulation can lead to improper authorization. It is possible to launch the attack remotely. Upgrading to version 9.6.0-rc1, 9.6.0 and 9.7.0-rc3 is sufficient to fix this issue. This patch is called 39d1276a63e95a7713f954dea632a19651d9cebb. You should upgrade the affected component.10hCVE-2026-852087.3 HIG—
———A security flaw has been discovered in itsourcecode Online Medicine Delivery System 1.0. The affected element is the function doInsert of the file /rider/orders/controller.php?action=add of the component Order Management Controller. Performing a manipulation of the argument image results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.12hCVE-2026-851866.3 MED—
———A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/controller.php?action=photos of the component Customer Controller. Executing a manipulation of the argument photo can lead to unrestricted upload. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.16hCVE-2026-848149.8 CRI—
———Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions.15h