CVE-2026-41539 Details
Description
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following versions: QTS 5.2.9.3492 build 20260507 and later QuTS hero h5.2.9.3499 build 20260514 and later QuTS hero h5.3.4.3500 build 20260520 and later QuTS hero h6.0.0.3500 build 20260520 and later
A cross-site scripting (XSS) vulnerability has been identified in several QNAP operating system versions. This vulnerability allows remote attackers to bypass security mechanisms or access application data. Affected QNAP operating systems include QTS versions prior to 5.2.9.3492 build 20260507, QuTS hero versions prior to h5.2.9.3499 build 20260514, QuTS hero h5.3.4.3500 build 20260520 and earlier, and QuTS hero h6.0.0.3500 build 20260520 and earlier.
Users can upgrade to QTS 5.2.9.3492 build 20260507 or later, or QuTS hero h5.2.9.3499 build 20260514 or later, QuTS hero h5.3.4.3500 build 20260520 or later, or QuTS hero h6.0.0.3500 build 20260520 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.qnap.com/en/security-advisory/qsa-26-10 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| qnap qts | 5.2.0.2737 build_20240417 5.2.0.2744 build_20240424 5.2.0.2782 build_20240601 5.2.0.2802 build_20240620 5.2.0.2823 build_20240711 5.2.0.2851 build_20240808 5.2.0.2860 build_20240817 5.2.1.2930 build_20241025 5.2.2.2950 build_20241114 5.2.3.3006 build_20250108 5.2.4.3070 build_20250312 5.2.4.3079 build_20250321 5.2.4.3092 build_20250403 5.2.5.3145 build_20250526 5.2.6.3195 build_20250715 5.2.6.3229 build_20250818 5.2.7.3256 build_20250913 5.2.7.3297 build_20251024 5.2.8.3332 build_20251128 5.2.8.3350 build_20251216 5.2.8.3359 build_20251225 5.2.9.3410 build_20260214 5.2.9.3451 build_20260327 |
CPE
Remediation
| |
| qnap quts hero | h5.2.0.2737 build_20240417 h5.2.0.2782 build_20240601 h5.2.0.2789 build_20240607 h5.2.0.2802 build_20240620 h5.2.0.2823 build_20240711 h5.2.0.2851 build_20240808 h5.2.0.2860 build_20240817 h5.2.1.2929 build_20241025 h5.2.1.2940 build_20241105 h5.2.2.2952 build_20241116 h5.2.3.3006 build_20250108 h5.2.4.3070 build_20250312 h5.2.4.3079 build_20250321 h5.2.5.3138 build_20250519 h5.2.6.3195 build_20250715 h5.2.7.3256 build_20250913 h5.2.7.3297 build_20251024 h5.2.8.3321 build_20251117 h5.2.8.3350 build_20251216 h5.2.8.3359 build_20251225 h5.2.9.3410 build_20260214 h5.2.9.3492 build_20260507 h5.3.0.3115 build_20250430 h5.3.0.3145 build_20250530 h5.3.0.3192 build_20250716 h5.3.1.3250 build_20250912 h5.3.1.3292 build_20251024 h5.3.2.3354 build_20251225 h5.3.3.3424 build_20260305 h6.0.0.3324 build_20251125 h6.0.0.3382 build_20260122 h6.0.0.3397 build_20260206 h6.0.0.3459 build_20260409 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 30, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 12, 2026 | Initial Analysis | [email protected] |
| Jun 9, 2026 | New CVE Received | [email protected] |