CVE-2026-30924Disclosure(getqui / qui)

LOWCVSS 9.6 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins while also returning Access-Control-Allow-Credentials: true, effectively allowing any external webpage to make authenticated requests on behalf of a logged-in user. An attacker can exploit this by tricking a victim into loading a malicious webpage, which silently interacts with the application using the victim's session and potentially exfiltrating sensitive data such as API keys and account credentials, or even achieving full system compromise through the built-in External Programs manager. Exploitation requires that the victim access the application via a non-localhost hostname and load an attacker-controlled webpage, making highly targeted social-engineering attacks the most likely real-world scenario. This issue was not fixed at the time of publication.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-942

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • qui

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-22)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
qui

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-19: 1Mentions · 2026-03-20: 1Mentions · 2026-03-22: 2Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 1Technical Details · 2026-03-22: 203-1903-2003-22
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-201
General1
2026-03-222
Disclosure2
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30924 qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins while also returning… https://www.cve.org/CVERecord?id=CVE-2026-30924 ----- Traducción: CVE-2026-30924 que… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-30924, noting a permissive CORS policy in qBittorrent’s web interface, but offers no evidence of exploits, patches, or active use.

    0000035
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-30924 qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins while also returning… https://www.cve.org/CVERecord?id=CVE-2026-30924

    Post summary

    The post discloses a CORS policy flaw in qBittorrent’s web interface, providing technical details but no PoC, exploit, active‑attack, or patch information.

    00000323
    56.8K followersView on X
  • PulsePatch.io@pulsepatchio
    General

    A critical CORS misconfiguration (CVE-2026-30924) allows arbitrary origins to access resources on affected systems. Review CORS policies to prevent potential data exposure. #infosec #CORS #securitymisconfiguration https://www.pulsepatch.io/posts/cve-2026-30924-cors-misconfiguration

    Post summary

    The post warns that CVE-2026-30924 is a critical CORS misconfiguration allowing arbitrary origins to access resources, urging readers to review CORS policies for protection.

    0000029
    1 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30924: qui CORS Misconfiguration: Arbit... Reflected origin CORS with credentials enabled = instant session hijacking via any malicious site—torrent management ju... https://zerodaysignal.com/vulnerability/CVE-2026-30924 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE‑2026‑30924, outlining a CORS misconfiguration that could enable session hijacking, but it does not provide PoC code, exploit details, or a patch. It serves primarily as a vulnerability disclosure.

    0000075
    154 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgetquiqui-docker-

Explore more