HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2026-44083

CVSS 8.7v4.0pub. 2026-06-09upd. 2026-06-12

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the vulnerability in the following version: QuMagie 2.9.1 and later

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Qnap Qumagie

    APP
    Qnap
    < 2.9.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-52425CRITICAL9.5PL ✓same product

SQL Injection w QNAP QuMagie umożliwiający zdalne wykonanie kodu

CVE-2026-26237HIGH8.7same product

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then explo...

CVE-2026-26236HIGH8.7same product

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then explo...

CVE-2025-58464HIGH7.8same product

A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can th...

CVE-2023-47560HIGH7.4same product

An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability cou...