Junglewise Threat Intelligence

CVE-2026-22895: QNAP QuFTP Service cross-site scripting

CVE-2026-22895 · Severity: medium · CVSS 4.8 · Published 2026-03-20

Vendors: QNAP.

Executive brief

QNAP QuFTP Service, a tool used to manage file transfers on QNAP storage devices, contains a security flaw that could allow an attacker with administrative access to run malicious scripts in another user's browser. If exploited, this could allow the attacker to bypass security controls or access sensitive application data. Users should update to the latest version of the QuFTP Service to protect their systems.

Technical details

A stored cross-site scripting (XSS) vulnerability (CWE-79) exists in QNAP QuFTP Service. The vulnerability is located in the web management interface and requires an attacker to have already obtained high-level (administrator) privileges. By injecting malicious scripts, the attacker can execute code in the context of another user's browser session, typically requiring some form of user interaction. This can lead to the bypass of security mechanisms or unauthorized access to application data. The issue is resolved in versions 1.4.3, 1.5.2, 1.6.2, and later.

Affected products

  • QNAP QuFTP Service 1.4.x before 1.4.3, 1.5.x before 1.5.2, 1.6.x before 1.6.2

Timeline

  • 2026-03-20: disclosed
  • 2026-03-20: advisory: Initial NVD publication
  • 2026-03-21: patched: QNAP advisory QSA-26-15 published

References