Junglewise Threat Intelligence

CVE-2026-24724: QNAP File Station incorrect authorization bypass

CVE-2026-24724 · Severity: info · CVSS 8.6 · Published 2026-06-10

Vendors: QNAP, QNAP Systems.

Executive brief

QNAP File Station is a web-based tool used to manage files on QNAP storage devices. A security flaw allows a user with a standard account to bypass security restrictions and access files or perform actions they should not be authorized to do. This could lead to the unauthorized viewing or modification of sensitive data stored on the device.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in QNAP File Station 6. The flaw allows a remote attacker who has already obtained a valid user account to bypass intended access control mechanisms. By exploiting this vulnerability, the attacker can gain unauthorized access to files or system functions beyond their assigned privileges. The vulnerability is addressed in File Station 5 version 5.5.6.5243 and later. The attack requires low privileges and no user interaction.

Affected products

  • QNAP File Station 6 Versions prior to 5.5.6.5243

Timeline

  • 2026-06-10: advisory: QNAP published security advisory QSA-26-29
  • 2026-06-10: patched: Fix released in version 5.5.6.5243

References