CVE-2026-22894

CWE-22Path Traversal3 documents3 sources
Severity
1.3LOW
EPSS
0.1%
top 79.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 11

Description

A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Affected Packages2 packages

CVEListV5qnap_systems_inc./file_station_55.5.x5.5.6.5190
NVDqnap/file_station5.5.6.46915.5.6.5190

🔴Vulnerability Details

2
CVEList
File Station 52026-02-11
GHSA
GHSA-pjf9-xcq9-w388: A path traversal vulnerability has been reported to affect File Station 62026-02-11
CVE-2026-22894 (LOW CVSS 1.3) | A path traversal vulnerability has | cvebase.io