CVE-2026-41539

MEDIUM WAF: High
CVSS 6.1 Published: 2026-06-09
CWE-79

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3500 build 20260520 and later

WAF Coverage Analysis

Cross-Site Scripting (XSS) High WAF Coverage

OWASP: A03:2021 Injection

941xxx - XSS / XXE

Affected Software

VendorProductVersion
qnapqts5.2.0.2737
qnapqts5.2.0.2744
qnapqts5.2.0.2782
qnapqts5.2.0.2802
qnapqts5.2.0.2823
qnapqts5.2.0.2851
qnapqts5.2.0.2860
qnapqts5.2.1.2930
qnapqts5.2.2.2950
qnapqts5.2.3.3006

References

Back to CVE Database