CVE-2026-67244
Received
Received - Intake
Format String Vulnerability in ADM Notification OAuth Settings
Vulnerability report for CVE-2026-67244, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-30
Last updated on: 2026-07-30
Assigner: ASUSTOR, Inc.
Description
Description
A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification configuration input may be processed through an unsafe format string operation. An authenticated administrator can exploit this issue to disclose memory information or cause denial of service of the affected component.
Affected products and versions include: from ADM 4.1.0 through ADM 4.3.3.RUN1 as well as from ADM 5.0.0 through ADM 5.1.3.RI81.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| asustor | adm | From 4.1.0 (inc) to 4.3.3 (inc) |
| asustor | adm | From 5.0.0 (inc) to 5.1.3 (inc) |
| asustor | adm | From 4.1.0 (inc) to 4.3.3.RUN1 (inc) |
| asustor | adm | From 5.0.0 (inc) to 5.1.3.RI81 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-134 | The product uses a function that accepts a format string as an argument, but the format string originates from an external source. |