CVE-2026-22898

CRITICAL

QNAP QVR Pro < 2.7.4.14 - Missing Authentication for Critical Function

Title source: manual
STIX 2.1

Description

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system. We have already fixed the vulnerability in the following version: QVR Pro 2.7.4.14 and later

Scores

CVSS v3 9.8
EPSS 0.0045
EPSS Percentile 63.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (2)
qnap/qvr_pro 2.7.1.1259 - 2.7.4.1485
QNAP Systems Inc./QVR Pro 2.7.x - 2.7.4.14
Published Mar 20, 2026
Tracked Since Mar 20, 2026