CVE-2026-22893
EUVD-2026-3597210.06.2026, 04:17
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3410 build 20260214 and later QuTS hero h5.2.9.3410 build 20260214 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| qnap | qts | 5.2.0.2737 ≤ 𝑥 < 5.2.9.3410 |
𝑥
= Vulnerable software versions