CVE-2026-24717Disclosure(qnap / qts)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3459 build 20260409 and later

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • qts
  • quts_hero

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
qtsquts_hero

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-26: 1Technical Details · 2026-06-26: 106-26
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • BREACHSPIDER@breachspider
    Disclosure

    [CVE Analysis] CVE-2026-24717: QNAP Path Traversal Exposes OT Backup and Historian Repositories https://breachspider.com/intel/2026-06-26-cve-2026-24717-qnap-path-traversal-exposes-ot-backup-and-his #ICS #OTSecurity #SCADA #CriticalInfrastructure

    Post summary

    The BreachSpider article announces CVE‑2026‑24717, a path‑traversal vulnerability that exposes QNAP OT backup and historian repositories to unauthorized access.

    0000050
    2.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSqnapqts---
OSqnapquts_hero---

Explore more