CVE-2026-22893 | QNAP QTS/QuTS hero 5.2.9.3410/5.3.4.3500/6.0.0.3459 os command injection (qsa-26-10)
A vulnerability classified as critical has been found in QNAP QTS and QuTS hero 5.2.9.3410/5.3.4.3500/6.0.0.3459. Affected is an unknown function. The manipulation leads to os command injection.
This vulnerability is documented as CVE-2026-22893. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.