- Description
- A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later
- Source
- security@qnapsecurity.com.tw
- NVD status
- Modified
- Products
- qumagie
CVSS 4.0
- Type
- Secondary
- Base score
- 6.6
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- MEDIUM
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- security@qnapsecurity.com.tw
- CWE-862
- Hype score
- Not currently trending
⚠️ Vulnerabilidades en productos QNAP ❗ CVE-2026-44083 ❗ CVE-2026-26237 ❗ CVE-2026-26236 ➡️ Más info: https://t.co/1kl6hvBqgH https://t.co/nngHyIoVl4
@CERTpy
1 Jul 2026
192 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
[CVE Analysis] CVE-2026-26236: Missing Authorization in QNAP QuMagie Exposes NAS-Adjacent OT Data Stores https://t.co/amDdJZFXgB #ICS #OTSecurity #SCADA #CriticalInfrastructure
@breachspider
28 Jun 2026
56 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:qumagie:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B04C9EA2-D3DA-4201-9509-E5D601C7A184",
"versionEndExcluding": "2.9.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]