Junglewise Threat Intelligence

CVE-2026-26237: QNAP QuMagie missing authorization vulnerability

CVE-2026-26237 · Severity: info · CVSS 8.7 · Published 2026-06-10

Vendors: QNAP.

Executive brief

A security vulnerability has been identified in QuMagie, a photo management application used on QNAP storage devices. This flaw allows unauthorized individuals to bypass security checks and access private photos or perform actions without permission. If exploited, this could lead to the exposure of sensitive personal media and a breach of user privacy.

Technical details

A missing authorization vulnerability (CWE-862) exists in QNAP QuMagie. The flaw allows a remote, unauthenticated attacker to bypass intended access controls due to insufficient validation of user permissions. Successful exploitation enables the attacker to access private personal information (CWE-359) or execute unauthorized functions within the application. The vulnerability is addressed in QuMagie version 2.9.0 and later.

Affected products

  • QNAP QuMagie Versions prior to 2.9.0

Timeline

  • 2026-06-10: advisory: Initial advisory published by QNAP and NVD.
  • 2026-06-10: patched: Vulnerability fixed in QuMagie 2.9.0.

References