CVE-2026-44083

Published Jun 9, 2026

Last updated 7 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-44083 describes an authorization bypass vulnerability found in QNAP's QuMagie, a photo management application designed for QNAP NAS devices. This flaw, categorized as CWE-639 (Authorization Bypass Through User-Controlled Key), allows remote attackers to exploit user-controlled keys to gain unintended privileges within the application. The vulnerability can be exploited over the network without requiring authentication or user interaction, increasing the exposure for internet-facing deployments of QuMagie. QNAP Systems, Inc. has addressed this issue, and a fix is available in QuMagie version 2.9.1 and later.

Description
An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the vulnerability in the following version: QuMagie 2.9.1 and later
Source
security@qnapsecurity.com.tw
NVD status
Analyzed
Products
qumagie

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.7
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

security@qnapsecurity.com.tw
CWE-639

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.