# CVE-2026-90508

## Summary

- **CVE ID:** CVE-2026-90508
- **Severity:** MEDIUM
- **CVSS Score:** 4.6 (CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P)
- **CWE:** CWE-862, CWE-863
- **Published:** Sep 13, 2026
- **Last Modified:** Sep 15, 2026

## Description

A security flaw has been discovered in Chengdu Qilu Technology Ludashi 6.1026.4715.714. Affected by this vulnerability is the function MessageNotifyCallback in the library ProtectFilter64.sys of the component Message Dispatch Handler. Performing a manipulation results in missing authorization. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

## Affected Products

- Chengdu Qilu Technology — Ludashi (6.1026.4715.714)

## References

- [CNA](https://vuldb.com/vuln/403096)
- [CNA](https://vuldb.com/vuln/403096/cti)
- [CNA](https://vuldb.com/cve/CVE-2026-90508)
- [CNA](https://vuldb.com/submit/895271)
- [CNA](https://gist.github.com/lzty/fc5f336dca4c287ab4c22168b6dc8ec2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.11%
- **EPSS Percentile:** 1.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._