CVE-2026-4047
Qinglong Case-sensitive Path Matching Authentication Bypass
Description
A vulnerability is present in Qinglong due to improperly matching case sensitive paths used by middleware authenticaion but the underlying Express.js framework treats paths case insensitively.
Description source: VulnCheck
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Apr 26, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
QinglongBrowse Qinglong / Qinglong | VulnCheck | Version data not supplied | |