A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions.
We have already fixed the vulnerability in the following version:
QuMagie 2.9.0 and later
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-26-10 |
|
History
Fri, 12 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap
Qnap qumagie |
|
| CPEs | cpe:2.3:a:qnap:qumagie:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Qnap
Qnap qumagie |
|
| Metrics |
cvssV3_1
|
Wed, 10 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap Systems
Qnap Systems qumagie |
|
| Vendors & Products |
Qnap Systems
Qnap Systems qumagie |
Wed, 10 Jun 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later | |
| Title | QuMagie | |
| Weaknesses | CWE-359 CWE-862 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published: 2026-06-10T03:15:03.739Z
Updated: 2026-06-10T15:37:12.207Z
Reserved: 2026-02-12T02:21:35.482Z
Link: CVE-2026-26237
Updated: 2026-06-10T15:26:03.010Z
Status : Analyzed
Published: 2026-06-10T04:17:19.067
Modified: 2026-06-12T19:53:02.280
Link: CVE-2026-26237
No data.
ReportizFlow