{"id":"CVE-2026-90508","title":"A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714","summary":"A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Pe…","severity":"low","cvss":3.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-862","CWE-863"],"vendor":"Chengdu Qilu Technology","product":"Ludashi","affected":["Ludashi 6.1026.4715.714"],"published":"2026-09-13","updated":"2026-09-15","sourceUpdated":"2026-09-15T15:17:27.790","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90508","references":[{"url":"https://gist.github.com/lzty/fc5f336dca4c287ab4c22168b6dc8ec2","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-90508","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/895271","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403096","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403096/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00112,"epssPercentile":0.0155,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T13:42:29.278243Z"},"ingestedAt":"2026-09-14T15:23:07.471Z","slug":"CVE-2026-90508","body":"## Overview\n\nA security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":31,"depthScoreParts":{"impact":18.7,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":203722,"id":"CVE-2026-90508","ts":1789483138587,"field":"exploit_available","old":"false","new":"true"}]}