Executive brief
An authorization bypass vulnerability has been identified in QuMagie, a photo management application for QNAP NAS devices. This flaw allows remote attackers to gain unauthorized access to the system and obtain elevated privileges. Exploitation could lead to the exposure of private media files and sensitive user data stored on the device.
Technical details
This vulnerability (CWE-639) involves an authorization bypass through a user-controlled key in QNAP QuMagie. The flaw allows a remote, unauthenticated attacker to manipulate keys or identifiers within requests to bypass security checks. By successfully exploiting this, an attacker can gain unintended privileges, potentially accessing data belonging to other users. The vulnerability is reachable over the network without user interaction. QNAP has addressed this issue in QuMagie version 2.9.1 and later.
Affected products
- QNAP Systems, Inc. QuMagie Versions prior to 2.9.1
Timeline
- 2026-06-09: advisory: QNAP security advisory QSA-26-35 published
- 2026-06-09: disclosed: CVE-2026-44083 published to NVD