CVE-2026-26237
Last modified
CVE-2026-26237 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the following version: QuMagie 2.9.0 and later
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qnap | Qumagie | < 2.9.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-26237?
How severe is CVE-2026-26237?
How do I fix CVE-2026-26237?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-26231Gitea versions up to and including 1.26.1 allow the Allow ed…8.5
- CVE-2026-26232Gitea versions before 1.25.5 do not consistently enforce OAu…9.1
- CVE-2026-26233Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2…6.5
- CVE-2026-26234JUNG Smart Visu Server 1.1.1050 contains a request header ma…8.8
- CVE-2026-26235JUNG Smart Visu Server 1.1.1050 contains a denial of service…8.7
- CVE-2026-26236A missing authorization vulnerability has been reported to a…7.5
- CVE-2026-26239A buffer overflow vulnerability has been reported to affect …8.1
- CVE-2026-2624Missing Authentication for Critical Function vulnerability i…9.8
- CVE-2026-26240A buffer overflow vulnerability has been reported to affect …9.1
- CVE-2026-26241A buffer overflow vulnerability has been reported to affect …9.1
- CVE-2026-26246Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.1…4.3
- CVE-2026-26247Gitea versions before 1.25.5 do not persist the OAuth2 PKCE …9.1
Are you affected by CVE-2026-26237?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
