HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2026-26236

CVSS 8.7v4.0pub. 2026-06-09upd. 2026-06-12

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Qnap Qumagie

    APP
    Qnap
    < 2.9.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-52425CRITICAL9.5PL ✓same product

SQL Injection w QNAP QuMagie umożliwiający zdalne wykonanie kodu

CVE-2026-26237HIGH8.7same product

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then explo...

CVE-2026-44083HIGH8.7same product

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The rem...

CVE-2025-58464HIGH7.8same product

A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can th...

CVE-2023-47560HIGH7.4same product

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability cou...