Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Hard‑coded Key in Quest KACE SMA Enables Secret Decryption and Privilege Escalation | |
| Weaknesses | CWE-321 CWE-330 |
|
| Metrics |
cvssV3_1
|
Tue, 28 Jul 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Quest
Quest kace Systems Deployment Appliance |
|
| Vendors & Products |
Quest
Quest kace Systems Deployment Appliance |
Mon, 27 Jul 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain privileged access to unrelated systems or services. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-07-28T14:54:54.862Z
Reserved: 2021-05-06T00:00:00.000Z
Link: CVE-2021-32086
Updated: 2026-07-28T14:34:51.627Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T15:30:04Z