CVE-2026-30924

Publication date 19 March 2026

Last updated 9 September 2026


Ubuntu priority

Cvss 3 Severity Score

9.6 · Critical

Score breakdown

Description

qui is a web interface for managing qBittorrent instances. Versions 1.14.1 and below use a permissive CORS policy that reflects arbitrary origins while also returning Access-Control-Allow-Credentials: true, effectively allowing any external webpage to make authenticated requests on behalf of a logged-in user. An attacker can exploit this by tricking a victim into loading a malicious webpage, which silently interacts with the application using the victim's session and potentially exfiltrating sensitive data such as API keys and account credentials, or even achieving full system compromise through the built-in External Programs manager. Exploitation requires that the victim access the application via a non-localhost hostname and load an attacker-controlled webpage, making highly targeted social-engineering attacks the most likely real-world scenario. This issue was not fixed at the time of publication.

Read the notes from the security team

Status

Package Ubuntu Release Status
qbittorrent 26.04 LTS resolute
Not affected
25.10 questing Ignored end of life, was needs-triage
24.04 LTS noble
Not affected
22.04 LTS jammy
Not affected
20.04 LTS focal
Not affected
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected

Notes


yomonokio

CVE is in qui (github.com/autobrr/qui), a separate Go web interface for managing qBittorrent instances. The Ubuntu qbittorrent package is a C++ Qt application that does not contain or bundle qui. qui is not packaged in Ubuntu.

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
qbittorrent

Severity score breakdown

CVSS version:

Base score 9.0 · Critical

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H

Base score 9.6 · Critical

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H


Access our resources on patching vulnerabilities