Junglewise Threat Intelligence

CVE-2026-26236: QNAP QuMagie missing authorization

CVE-2026-26236 · Severity: info · CVSS 8.7 · Published 2026-06-09

Vendors: QNAP Systems, Inc..

Executive brief

QNAP QuMagie, a photo management application for NAS devices, contains a security flaw that allows unauthorized access to data. Remote attackers can exploit this to view private photos or perform actions without proper permission. This could lead to the exposure of sensitive personal or corporate media stored on the device.

Technical details

A missing authorization vulnerability (CWE-862) exists in QNAP QuMagie. The flaw allows a remote, unauthenticated attacker to bypass intended access controls due to insufficient validation of user permissions. By sending crafted requests over the network, an attacker can access sensitive data or execute unauthorized functions within the application. The vulnerability is addressed in QuMagie version 2.9.0 and later.

Affected products

  • QNAP Systems, Inc. QuMagie Versions prior to 2.9.0

Timeline

  • 2026-06-09: advisory: Initial publication of QSA-26-36 and CVE-2026-26236
  • 2026-06-09: patched: Fix released in QuMagie 2.9.0

References

Related threats