CVE-2026-30896

Severity CVSS v4.0:
HIGH
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
09/03/2026
Last modified:
10/03/2026

Description

The installer for Qsee Client versions 1.0.1 and prior insecurely load Dynamic Link Libraries (DLLs). When a user is directed to place some malicious DLL to the same directory and execute the affected installer, then arbitrary code may be executed with the administrative privilege.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:q-see:qsee_client:*:*:*:*:*:windows:*:* 1.0.1 (including)