安全ID : QSA-26-35
Vulnerabilities in QuMagie and License Center
发布日期 : March 10, 2026
通用漏洞披露 : CVE-2026-26236, CVE-2026-26237, CVE-2026-44083
受影响产品: QuMagie 2.9.0, QuMagie2.8.2, License Center 1.8.56
严重程度
严重
状态
已解决
Summary
Multiple vulnerabilities have been reported to affect QuMagie:
- CVE-2026-26236: Pre-authentication vulnerability
An unauthenticated remote attacker may access media files stored in QuMagie, potentially resulting in information disclosure.
- CVE-2026-26237: Pre-authentication vulnerability
An unauthenticated remote attacker may access AI face recognition thumbnails and folder cover images, potentially resulting in information disclosure.
- CVE-2026-44083: Unauthorized access vulnerability
An unauthenticated remote attacker may gain unauthorized access to media files and album archives stored in QuMagie, potentially resulting in information disclosure.
- CVE-2025-62851:Path traversal
An authenticated administrator may access files outside the intended directory due to a path traversal vulnerability in qlicenseRequest.cgi.
We have already fixed the vulnerabilities in the following version:
| Affected Product | Fixed Version |
| QuMagie 2.8.2 | QuMagie 2.9.1 |
| QuMagie 2.9.0 | QuMagie 2.10.0 |
| License Center 1.8.56 | License Center 2.0.42 |
Recommendation
To secure your device, we recommend regularly updating your system to the latest version to benefit from vulnerability fixes. You can check the product support status to see the latest updates available to your NAS model.
Updating QuMagie
- Log on to QTS or QuTS hero as an administrator.
- Open App Center and then click
.
A search box appears. - Type "QuMagie" and then press ENTER.
QuMagie appears in the search results. - Click Update.
A confirmation message appears.
Note: The Update button is not available if your QuMagie is already up to date. - Click OK.
The system updates the application.
Updating License Center
- Log on to QTS or QuTS hero as an administrator.
- Open App Center and then click
.
A search box appears. - Type "License Center" and then press ENTER.
License Center appears in the search results. - Click Update.
A confirmation message appears.
Note: The Update button is not available if your License Center is already up to date. - Click OK.
The system updates the application.
附件
修订历史:
V1.0 (June 17, 2026) - Published