What is CVE-2026-18188?
This critical format string vulnerability affects the Rsync Backup feature on ADM. It occurs because user-controlled backup configuration or log data is processed through an unsafe format string operation. An authenticated attacker can exploit this flaw to read sensitive memory information from the system.
Azərbaycanca: Bu kritik format string zəifliyi ADM üzərindəki Rsync Backup funksiyasına təsir edir. İstifadəçi tərəfindən idarə olunan backup konfiqurasiya və ya log məlumatlarının təhlükəsiz olmayan format string əməliyyatı ilə işlənməsi nəticəsində yaranır. Doğrulanmış hücumçu bu boşluqdan istifadə edərək sistemin yaddaş məlumatlarını oxuya bilər.
FAQ1
Which feature of ASUSTOR ADM is affected by CVE-2026-18188?
CVE-2026-18188 is a critical format string vulnerability affecting the Rsync Backup feature on ADM.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.