A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions.
We have already fixed the vulnerability in the following version:
QuMagie 2.9.0 and later
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-26-36 |
|
History
Tue, 09 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Jun 2026 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap Systems
Qnap Systems qumagie |
|
| Vendors & Products |
Qnap Systems
Qnap Systems qumagie |
Tue, 09 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later | |
| Title | QuMagie | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published: 2026-06-09T04:06:37.135Z
Updated: 2026-06-09T13:18:08.708Z
Reserved: 2026-02-12T02:21:35.482Z
Link: CVE-2026-26236
Updated: 2026-06-09T13:18:03.885Z
Status : Awaiting Analysis
Published: 2026-06-09T05:16:34.453
Modified: 2026-06-09T13:49:39.993
Link: CVE-2026-26236
No data.