CVE-2026-24717
Received
Received - Intake
Path Traversal in QNAP QTS and QuTS hero
Publication date: 2026-06-10
Last updated on: 2026-06-10
Assigner: QNAP Systems, Inc.
Description
Description
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data.
We have already fixed the vulnerability in the following versions:
QTS 5.2.9.3492 build 20260507 and later
QuTS hero h5.2.9.3499 build 20260514 and later
QuTS hero h5.3.4.3500 build 20260520 and later
QuTS hero h6.0.0.3459 build 20260409 and later
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| qnap | qts | From 5.2.9.3492 (inc) |
| qnap | quts_hero | From h5.2.9.3499 (inc) |
| qnap | quts_hero | From h5.3.4.3500 (inc) |
| qnap | quts_hero | From h6.0.0.3459 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-22 | The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory. |