Description
A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vulnerability to bypass security mechanisms or read application data.

We have already fixed the vulnerability in the following version:
QcalAgent 1.1.9 and later
Published: 2026-09-18
Score: 5.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site scripting allowing local attackers to bypass security controls and read application data
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a cross‑site scripting flaw in QcalAgent that allows an attacker who has local access to inject malicious scripts into the application. By exploiting this flaw the attacker can bypass built‑in security controls or read protected application data. This is a typical client‑side injection weakness classified as CWE‑79.

Affected Systems

The issue affects QNAP Systems Inc.'s QcalAgent component. All released versions prior to 1.1.9 contain the vulnerability; versions 1.1.9 and later contain the fix.

Risk and Exploitability

The CVSS score of 5.2 indicates a medium severity. The EPSS score of less than 1% suggests a low probability of exploitation at the time of this analysis, and the flaw is not yet listed in CISA’s KEV catalog. The likely attack vector is local; an adversary with physical or administrative access to the device can submit crafted requests that trigger the XSS. Once executed, the injected script can use the browser context to read cookies, session tokens, and other data exposed by QcalAgent, potentially allowing further privilege escalation.

Generated by OpenCVE AI on September 19, 2026 at 20:29 UTC.

Remediation

Vendor Solution

We have already fixed the vulnerability in the following version: QcalAgent 1.1.9 and later


OpenCVE Recommended Actions

  • Upgrade QcalAgent to version 1.1.9 or later to fix the XSS flaw.
  • If an upgrade is not immediately possible, isolate the QcalAgent service from the network or restrict access to trusted administrators only, limiting the local attack surface.
  • Implement monitoring of web access logs and input patterns to detect potential exploitation attempts.

Generated by OpenCVE AI on September 19, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Qnap
Qnap qcalagent
Vendors & Products Qnap
Qnap qcalagent

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QcalAgent 1.1.9 and later
Title QcalAgent
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: qnap

Published:

Updated: 2026-09-18T14:31:44.541Z

Reserved: 2024-02-20T09:36:58.211Z

Link: CVE-2024-27123

cve-icon Vulnrichment

Updated: 2026-09-18T14:30:04.727Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:48.117

Modified: 2026-09-28T14:10:00.213

Link: CVE-2024-27123

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:30Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')