CVE-2026-22898

Severity CVSS v4.0:
CRITICAL
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
20/03/2026
Last modified:
14/04/2026

Description

A missing authentication for critical function vulnerability has been reported to affect QVR Pro. The remote attackers can then exploit the vulnerability to gain access to the system.<br /> <br /> We have already fixed the vulnerability in the following version:<br /> QVR Pro 2.7.4.14 and later

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qnap:qvr_pro:*:*:*:*:*:*:*:* 2.7.1.1259 (including) 2.7.4.1485 (excluding)


References to Advisories, Solutions, and Tools