Junglewise Threat Intelligence

CVE-2026-22899: QNAP File Station NULL pointer dereference in File Station 6

CVE-2026-22899 · Severity: info · CVSS 5.3 · Published 2026-06-10

Vendors: QNAP.

Executive brief

QNAP File Station, a web-based application for managing files on QNAP NAS devices, is affected by a security flaw that could allow a user to crash the service. An attacker who already has a valid user account on the system can trigger this issue to cause a denial-of-service, making the file management interface unavailable to other users. This impact is limited to service availability and does not involve the theft of data or unauthorized access to files.

Technical details

A NULL pointer dereference (CWE-476) exists in QNAP File Station 6. The vulnerability is reachable over the network but requires the attacker to possess valid user credentials (low privileges). By sending a specifically crafted request that triggers the NULL pointer dereference, an attacker can cause the application to crash, resulting in a denial-of-service. The vendor has released a fix in File Station version 5.5.6.5208 and later.

Affected products

  • QNAP File Station 6 Versions prior to 5.5.6.5208

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References

Related threats