Home

Description

A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3500 build 20260520 and later

PUBLISHED Reserved 2026-04-21 | Published 2026-06-09 | Updated 2026-06-09 | Assigner qnap




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-79

Product status

Default status
unaffected

5.2.0 (custom) before 5.2.9.3492 build 20260507
affected

Default status
unaffected

h5.2.0 (custom) before h5.2.9.3499 build 20260514
affected

h5.3.0 (custom) before h5.3.4.3500 build 20260520
affected

? (custom) before h6.0.0.3500 build 20260520
affected

References

www.qnap.com/en/security-advisory/qsa-26-31

cve.org (CVE-2026-41539)

nvd.nist.gov (CVE-2026-41539)

Download JSON