Back to Database
Status published
Critical
CVE-2025-26850
The agent in Quest KACE Systems Management Appliance (SMA) before...
Vulnerability Description
The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-26850
Credits & Attribution
No credits recorded in the NVD database.
References
More from Quest
View All →CVE-2025-12874
HTTP Request Smuggling in Quest Coexistence Manager for Notes
Medium
6.3
CVE-2020-8868
This vulnerability allows remote attackers to execute arbitrary code on...
Critical
9.8
CVE-2018-1163
This vulnerability allows remote attackers to bypass authentication on vulnerable...
Critical
9.8
CVE-2018-1162
This vulnerability allows remote attackers to create a denial-of-service condition...
High
8.1
CVE-2018-1161
This vulnerability allows remote attackers to execute arbitrary code on...
Critical
9.8
Affected Vendor
Quest
View all reports →Affected Software
KACE Systems Management Appliance
Vulnerable Versions:
0, 14.1.0
Timeline
Official Publish:
July 4th, 2025
Last Modified:
July 8th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H