Executive brief
A security vulnerability has been identified in QNAP Notification Center, a tool used to manage system alerts and notifications on QNAP NAS devices. An attacker could trick a logged-in user into performing unintended actions, potentially allowing the attacker to gain unauthorized privileges or hijack the user's identity. This could lead to unauthorized changes to system notification settings or broader access to the device management interface.
Technical details
A cross-site request forgery (CSRF) vulnerability (CWE-352) exists in QNAP Notification Center versions 1.10.x. The flaw allows a remote attacker to execute unauthorized actions in the context of a victim's browser session, provided the victim is authenticated to the QNAP management interface and interacts with a malicious link or site. Successful exploitation can lead to privilege escalation or session hijacking. The vulnerability is addressed in Notification Center version 1.10.0.3291 and later.
Affected products
- QNAP Systems, Inc. Notification Center 1.10.x prior to 1.10.0.3291
Timeline
- 2026-03-10: advisory: Initial advisory published by QNAP (QSA-26-13)
- 2026-06-10: disclosed: NVD publication date