CVE-2026-25628Disclosure(qdrant / qdrant)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch qdrant qdrant systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_disk.log_file path. Minimal privileges are required (read-only access). This vulnerability is fixed in 1.16.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • qdrant

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-02-06)
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
qdrant

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-05: 1Mentions · 2026-02-06: 3Patch / Workaround · 2026-02-06: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-06: 302-0502-06
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-051
General1
2026-02-063
Disclosure2Patch1
Full discourse4 posts
  • ezzer@ez_z3r
    General

    Recently had the worst possible experience of reporting to @huntr_ai CVE-2026-25628: - Report mistakenly marked duplicate - High-severity RCE vulnerability disclosed before fix - Requests to support ignored The vuln is interesting too, read more at https://blog.z3r.ru/posts/qdrant-rce/

    Post summary

    The user reports a high‑severity RCE vulnerability (CVE‑2026‑25628) that was prematurely disclosed and marked duplicate, noting lack of support and linking to a blog for additional details.

    10030127
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25628 Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using a… https://www.cve.org/CVERecord?id=CVE-2026-25628

    Post summary

    The text announces CVE-2026-25628, detailing a file‑append vulnerability in Qdrant 1.9.3‑1.15.x via the /logger endpoint, without indicating PoC, exploitation, or patches.

    01000220
    56.5K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-25628: HIGH] Vector similarity search engine Qdrant had a vulnerability (fixed in 1.16.0) allowing file manipulation on versions up to 1.9.3 via /logger endpoint with attacker-controlled path.#cve,CVE-2026-25628,#cybersecurity https://cvefind.com/CVE-2026-25628

    Post summary

    Qdrant’s CVE‑2026‑25628 allows attacker-controlled file manipulation via the /logger endpoint on versions up to 1.9.3 and is fixed in version 1.16.0.

    0000055
    583 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-25628 - High Qdrant is a vector similarity search engine and vector database. From 1.9.3 to before 1.16.0, it is possible to append to arbitrary files via /logger endpoint using an attacker-controlled on_... https://www.thehackerwire.com/vulnerability/CVE-2026-25628/ https://t.co/FlVGMkqMp7

    Post summary

    The text announces CVE-2026-25628, describing how Qdrant versions 1.9.3 to before 1.16.0 allow attackers to append to arbitrary files via the /logger endpoint, but it does not provide a PoC, exploit code, or patch details.

    0000053
    113 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appqdrantqdrant---

Explore more