Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-67244

CVE-2026-67244: ADM Format String Vulnerability

CVE-2026-67244 is a format string vulnerability in ADM Notification OAuth settings that allows authenticated administrators to disclose memory information or cause denial of service. This article covers technical details, affected versions, impact, and mitigation steps.

Published:

CVE-2026-67244 Overview

CVE-2026-67244 is a format string vulnerability [CWE-134] in the Notification OAuth settings component of ASUSTOR Data Master (ADM). The flaw exists because user-controlled notification configuration input is passed to an unsafe format string operation. An authenticated administrator can exploit this issue to disclose memory contents or trigger a denial of service in the affected component. The vulnerability affects ADM 4.1.0 through 4.3.3.RUN1 and ADM 5.0.0 through 5.1.3.RI81, as documented in the Asustor Security Advisory #67.

Critical Impact

Authenticated administrators can leverage the format string flaw to leak memory or crash the notification component, undermining confidentiality and availability of the network-attached storage device.

Affected Products

  • ASUSTOR ADM 4.1.0 through 4.3.3.RUN1
  • ASUSTOR ADM 5.0.0 through 5.1.3.RI81
  • ADM Notification OAuth settings component

Discovery Timeline

  • 2026-07-30 - CVE-2026-67244 published to NVD
  • 2026-07-30 - Last updated in NVD database

Technical Details for CVE-2026-67244

Vulnerability Analysis

The vulnerability resides in the Notification OAuth settings interface of ADM, ASUSTOR's operating system for its network-attached storage (NAS) appliances. The affected code path processes administrator-supplied OAuth configuration values and forwards them into a routine that treats attacker-controlled data as a format string. When format specifiers such as %s, %x, or %n appear in that input, the underlying printf-family function interprets them as directives instead of literal characters.

Exploitation of the flaw yields two primary outcomes documented in the vendor advisory. First, attackers can read out-of-bounds stack or heap memory, exposing sensitive process data. Second, malformed specifiers can dereference invalid pointers and terminate the notification component, producing a denial of service. Exploitation requires an authenticated session with administrative privileges, which limits the attacker population but does not eliminate risk in shared or federated environments.

Root Cause

The root cause is classic improper use of a format string [CWE-134]. The Notification OAuth handler passes user input directly as the format argument to a formatting function rather than using a fixed format string with the input supplied as a parameter. Any format specifier present in the OAuth configuration values is interpreted by the C runtime.

Attack Vector

The attack is delivered over the network against ADM's management interface. An authenticated administrator submits crafted OAuth notification settings that contain format specifiers. The affected component processes the input and executes the format string operation, resulting in memory disclosure or a component crash.

Exploitation described in prose only. No verified public proof-of-concept
code is available for CVE-2026-67244. Refer to the Asustor Security
Advisory #67 for vendor-supplied technical details.

Detection Methods for CVE-2026-67244

Indicators of Compromise

  • Unexpected crashes or restarts of the ADM notification service on affected NAS appliances
  • Notification OAuth configuration entries containing format specifier characters such as %s, %x, %p, or %n
  • Administrator audit log entries showing modifications to Notification OAuth settings from unfamiliar source IPs

Detection Strategies

  • Review ADM audit logs for changes to Notification OAuth configuration fields and compare submitted values against expected OAuth token and URL formats
  • Alert on process termination or watchdog restarts affecting the ADM notification daemon
  • Baseline administrative logins to the ADM web interface and flag sessions that modify notification settings outside of change windows

Monitoring Recommendations

  • Forward ADM system and audit logs to a centralized logging platform for correlation with administrator authentication events
  • Monitor network traffic to the ADM management interface for anomalous administrative activity, particularly from external networks
  • Track firmware version inventory across NAS fleet to confirm patched builds are deployed

How to Mitigate CVE-2026-67244

Immediate Actions Required

  • Upgrade ADM to a fixed release as identified in Asustor Security Advisory #67
  • Restrict access to the ADM administrative web interface to trusted management networks only
  • Audit existing administrator accounts and remove or rotate credentials that are no longer required
  • Review current Notification OAuth configuration entries for suspicious values containing format specifiers

Patch Information

ASUSTOR has published fixes in ADM releases succeeding 4.3.3.RUN1 in the 4.x branch and 5.1.3.RI81 in the 5.x branch. Consult the Asustor Security Advisory #67 for the exact fixed build numbers and download links applicable to each supported NAS model.

Workarounds

  • Block administrative access to the ADM interface from untrusted networks using firewall or VLAN segmentation
  • Disable OAuth-based notification integrations until patched firmware is installed
  • Enforce multi-factor authentication for administrator accounts to reduce the risk of credential-based abuse
bash
# Example: restrict ADM management access at the network perimeter
iptables -A INPUT -p tcp --dport 8000 -s 10.0.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 8000 -j DROP
iptables -A INPUT -p tcp --dport 8001 -s 10.0.0.0/24 -j ACCEPT
iptables -A INPUT -p tcp --dport 8001 -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.