{"document":{"category":"csaf_vex","csaf_version":"2.0","title":"CVE-2026-26236: QuMagie","publisher":{"category":"vendor","name":"HarborGuard Database","namespace":"https://database.harborguard.co"},"tracking":{"id":"CVE-2026-26236","status":"final","version":"1","initial_release_date":"2026-06-09T04:06:37.135Z","current_release_date":"2026-06-09T13:18:08.708Z","revision_history":[{"date":"2026-06-09T04:06:37.135Z","number":"1","summary":"Initial machine-readable export from HarborGuard."}]},"distribution":{"tlp":{"label":"WHITE"},"text":"Public CVE data; freely redistributable."},"notes":[{"category":"description","text":"A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions.\n\nWe have already fixed the vulnerability in the following version:\nQuMagie 2.9.0 and later","title":"CVE description"}],"references":[{"category":"self","summary":"CVE-2026-26236 on HarborGuard Database","url":"https://database.harborguard.co/cve/CVE-2026-26236"},{"category":"external","summary":"CVE Record","url":"https://www.cve.org/CVERecord?id=CVE-2026-26236"},{"category":"external","summary":"qnap.com","url":"https://www.qnap.com/en/security-advisory/qsa-26-36"}]},"product_tree":{"branches":[{"category":"vendor","name":"QNAP Systems Inc.","branches":[{"category":"product_name","name":"QuMagie","branches":[{"category":"product_version_range","name":">=2.9.0 <2.9.0","product":{"name":"QNAP Systems Inc. QuMagie >=2.9.0 <2.9.0","product_id":"CSAFPID-1","product_identification_helper":{"cpe":"cpe:2.3:a:qnap_systems_inc.:qumagie:*:*:*:*:*:*:*:*"}}}]}]}]},"vulnerabilities":[{"cve":"CVE-2026-26236","title":"QuMagie","notes":[{"category":"description","text":"A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions.\n\nWe have already fixed the vulnerability in the following version:\nQuMagie 2.9.0 and later","title":"CVE description"}],"product_status":{"known_affected":["CSAFPID-1"]},"scores":[{"cvss_v4":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","baseScore":8.7,"baseSeverity":"HIGH"},"products":["CSAFPID-1"]}],"remediations":[{"category":"vendor_fix","details":"Update to a fixed version: 2.9.0.","product_ids":["CSAFPID-1"]}]}]}