{"id":"CVE-2026-81326","title":"QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password.","summary":"QND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password.","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-321"],"vendor":"QualitySoft Corporation","product":"QND Premium","affected":["qnd_premium <= Ver.11.1i","qnd_standard <= Ver.11.1i","qnd_advance <= Ver.11.0.9i"],"published":"2026-09-16","updated":"2026-09-16","sourceUpdated":"2026-09-16T19:27:25.623","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-81326","references":[{"url":"https://jvn.jp/en/jp/JVN95825631/","label":"vultures@jpcert.or.jp"},{"url":"https://www.qualitysoft.com/product/qnd_vulnerabilities_2026/","label":"vultures@jpcert.or.jp"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-16T14:56:57.418397Z"},"ingestedAt":"2026-09-16T07:51:48.493Z","epss":0.00138,"epssPercentile":0.02558,"slug":"CVE-2026-81326","body":"## Overview\n\nQND uses a hard-coded cryptographic key, which may allow a local attacker who is logged in to a Windows PC where the affected product's client is installed to obtain administrator credentials, including an ID and password.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}