Multiple Vulnerabilities in Quanos Content Solutions SCHEMA ST4
All on-premise versions of SCHEMA ST4 are affected by a local privilege escalation vulnerability that can also result in arbitrary file overwrite. The vulnerabilities originate from the Update Service’s .NET Remoting interface. Both allow low-privileged local users to execute code or perform file operations with SYSTEM privileges. The vendor provides a workaround to disable the affected update service. CVE-2026-11857, CVE-2026-11858.


