Junglewise Threat Intelligence

CVE-2026-26239: QNAP File Station 5 stack-based buffer overflow

CVE-2026-26239 · Severity: info · CVSS 8.7 · Published 2026-06-10

Technologies: QNAP Systems, Inc. File Station 5. Vendors: QNAP Systems, Inc..

Executive brief

A security vulnerability has been identified in QNAP File Station 5, a web-based tool used for managing files on QNAP storage devices. If an attacker obtains access to a standard user account, they can exploit this flaw to crash system processes or modify sensitive memory. This could lead to a total loss of system availability or unauthorized control over the storage device.

Technical details

A stack-based buffer overflow (CWE-121) exists in QNAP File Station 5. The vulnerability is reachable over the network and requires the attacker to have authenticated access with a standard user account (PR:L). By sending specially crafted input, an attacker can overflow a buffer on the stack to modify memory or crash processes, potentially leading to arbitrary code execution. The issue is resolved in File Station 5 version 5.5.6.5208 and later.

Affected products

  • QNAP Systems, Inc. File Station 5 versions prior to 5.5.6.5208

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: advisory

References

Related threats