Executive brief
A security vulnerability has been identified in QNAP License Center, a tool used to manage software licenses on QNAP NAS devices. If an attacker manages to obtain administrator credentials, they can exploit this flaw to access sensitive system files that should normally be restricted. This could lead to the exposure of confidential system data or configuration information.
Technical details
A path traversal vulnerability (CWE-22) exists in QNAP License Center due to improper limitation of a pathname to a restricted directory. An attacker with high privileges (administrator account) can exploit this via the network to bypass directory restrictions and read the contents of unexpected files or system data. While the initial advisory mentions a 'local' attacker, the CVSS 4.0 vector provided by the vendor (AV:N) indicates the vulnerability is reachable over the network. The issue is resolved in License Center version 1.9.56 and later.
Affected products
- QNAP License Center versions prior to 1.9.56
Timeline
- 2026-06-10: advisory: QNAP published security advisory QSA-26-28
- 2026-06-10: disclosed