CVE-2026-67244
CVE-2026-67244 is a high-severity vulnerability in Asustor Data Master with a CVSS 3.x base score of 7.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-134.
Key facts
- Severity: High (CVSS 3.x base score 7.2)
- CVSS v4: 8.6
- EPSS exploit prediction: 0% (20th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-134
- Affected product: Asustor Data Master
- Published:
- Last modified:
Description
A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through an unsafe format string operation. An authenticated administrator can exploit this issue to disclose memory information or cause denial of service of the affected component. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
Frequently asked questions
- What is CVE-2026-67244?
- A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through an unsafe format string operation. An authenticated administrator can exploit this issue to disclose memory information or cause denial of service of the affected component. Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
- How severe is CVE-2026-67244?
- CVE-2026-67244 has a CVSS 3.x base score of 7.2, rated high severity. It is exploitable over network with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2026-67244 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (20th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-67244?
- CVE-2026-67244 affects Asustor Data Master. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-67244?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-67244 published?
- CVE-2026-67244 was published on 2026-07-30 and last updated on 2026-08-04.
References
Affected products (1)
- cpe:2.3:o:asustor:data_master:*:*:*:*:*:*:*:*
More vulnerabilities in Asustor Data Master
- CVE-2026-6643 — Critical (CVSS 9.9): A stack-based buffer overflow vulnerability was found in the VPN Clients on the ADM. The issue stems from the use of…
- CVE-2026-24936 — Critical (CVSS 9.8): When a specific function is enabled while joining a AD Domain from ADM, an improper input parameters validation…
- CVE-2018-12313 — Critical (CVSS 9.8): OS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without…
- CVE-2026-6644 — Critical (CVSS 9.1): A command injection vulnerability was found in the PPTP VPN Clients on the ADM. The vulnerability allows an…
- CVE-2026-67248 — High (CVSS 8.8): A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM. The vulnerability occurs because…
- CVE-2023-2910 — High (CVSS 8.8): Improper neutralization of special elements used in a command ('Command Injection') vulnerability in Printer service…
All CVEs affecting Asustor Data Master →
Other CWE-134 vulnerabilities
- CVE-2012-1851 — Critical (CVSS 10.0): Format string vulnerability in the Print Spooler service in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2,…
- CVE-2012-0242 — Critical (CVSS 10.0): Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary…
- CVE-2011-2475 — Critical (CVSS 10.0): Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server…
- CVE-2011-1568 — Critical (CVSS 10.0): Format string vulnerability in the logText function in shmemmgr9.dll in IGSSdataServer.exe 9.00.00.11074, and…
- CVE-2010-4235 — Critical (CVSS 10.0): Format string vulnerability in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server…
- CVE-2011-0270 — Critical (CVSS 10.0): Format string vulnerability in nnmRptConfig.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows…