AI description
CVE-2026-44083 describes an authorization bypass vulnerability found in QNAP's QuMagie, a photo management application designed for QNAP NAS devices. This flaw, categorized as CWE-639 (Authorization Bypass Through User-Controlled Key), allows remote attackers to exploit user-controlled keys to gain unintended privileges within the application. The vulnerability can be exploited over the network without requiring authentication or user interaction, increasing the exposure for internet-facing deployments of QuMagie. QNAP Systems, Inc. has addressed this issue, and a fix is available in QuMagie version 2.9.1 and later.
- Description
- An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have already fixed the vulnerability in the following version: QuMagie 2.9.1 and later
- Source
- security@qnapsecurity.com.tw
- NVD status
- Analyzed
- Products
- qumagie
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- security@qnapsecurity.com.tw
- CWE-639
- Hype score
- Not currently trending
⚠️ Vulnerabilidades en productos QNAP ❗ CVE-2026-44083 ❗ CVE-2026-26237 ❗ CVE-2026-26236 ➡️ Más info: https://t.co/1kl6hvBqgH https://t.co/nngHyIoVl4
@CERTpy
1 Jul 2026
192 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
QNAPのNAS向け写真管理アプリQuMagieに、認証なしでプライベート写真やAI顔認識サムネイルを外部から取得できる脆弱性3件が報告されています。最も深刻なCVE-2026-44083はCritical評価で、認証不要のリモート攻撃者
@MalwareBibleJP
24 Jun 2026
1346 Impressions
3 Retweets
9 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:qnap:qumagie:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B04C9EA2-D3DA-4201-9509-E5D601C7A184",
"versionEndExcluding": "2.9.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]