CVE-2026-24724
published 2026-06-10CVE-2026-24724: An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the…
PriorityP353high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
0.26%
17.5th percentile
An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass intended access restrictions.
We have already fixed the vulnerability in the following version:
File Station 5 5.5.6.5243 and later
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| qnap | file_station | >= 5.5.6.4691 < 5.5.6.5243 | 5.5.6.5243 |
| qnap_systems_inc | file_station_5 | >= 5.5.0 < 5.5.6.5243 | 5.5.6.5243 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv4.08.6HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
QNAP File Station 5 5.5.6.5243 User Account authorization (qsa-26-29 / EUVD-2026-35980)
vuldb·2026-06-15·CVSS 8.1
CVE-2026-24724 [HIGH] QNAP File Station 5 5.5.6.5243 User Account authorization (qsa-26-29 / EUVD-2026-35980)
A vulnerability identified as critical has been detected in QNAP File Station 5 5.5.6.5243. This impacts an unknown function of the component User Account Handler. Performing a manipulation results in incorrect authorization.
This vulnerability is identified as CVE-2026-24724. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
GHSA
An incorrect authorization vulnerability has been reported to affect File Station 6.
ghsa_unreviewed·2026-06-10
CVE-2026-24724 [HIGH] CWE-863 An incorrect authorization vulnerability has been reported to affect File Station 6.
An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass intended access restrictions.
We have already fixed the vulnerability in the following version:
File Station 5 5.5.6.5243 and later
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-10
Published