CVE-2026-10880 – Unauthenticated SQL Injection in Osnexus Quantastor

​CVE ID :CVE-2026-10880

Published : June 4, 2026, 5:19 p.m. | 1 hour, 1 minute ago

Description :OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly sanitized before being incorporated into a SQL query, allowing an unauthenticated remote attacker to bypass authentication and log in as an administrator without supplying a valid password.

Severity: 9.8 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More