Executive brief
QNAP File Station is a web-based tool used to manage files on QNAP storage devices. A security flaw allows a user with a standard account to bypass security restrictions and access files or perform actions they should not be authorized to do. This could lead to the unauthorized viewing or modification of sensitive data stored on the device.
Technical details
An incorrect authorization vulnerability (CWE-863) exists in QNAP File Station 6. The flaw allows a remote attacker who has already obtained a valid user account to bypass intended access control mechanisms. By exploiting this vulnerability, the attacker can gain unauthorized access to files or system functions beyond their assigned privileges. The vulnerability is addressed in File Station 5 version 5.5.6.5243 and later. The attack requires low privileges and no user interaction.
Affected products
- QNAP File Station 6 Versions prior to 5.5.6.5243
Timeline
- 2026-06-10: advisory: QNAP published security advisory QSA-26-29
- 2026-06-10: patched: Fix released in version 5.5.6.5243