LOWVulnerability

CVE-2026-90508

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Properties

severity
LOW
score
3.4
cve_id
CVE-2026-90508
signal_observed_at
2026-09-22T07:14:24+00:00
vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
published_at
2026-09-13T10:16:55.900
last_modified
2026-09-15T15:17:27.790

Related Entities (3)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (2)

[Weakness]Incorrect Authorization
[Weakness]Missing Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90508 — Ninja Signal Threat Intelligence | Ninja Signal