We have already fixed the vulnerability in the following version:
QcalAgent 1.1.9 and later
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
We have already fixed the vulnerability in the following version: QcalAgent 1.1.9 and later
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-24-54 |
|
Sat, 19 Sep 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap
Qnap qcalagent |
|
| Vendors & Products |
Qnap
Qnap qcalagent |
Sat, 19 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 18 Sep 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site scripting (XSS) vulnerability has been reported to affect QcalAgent. The local attackers can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: QcalAgent 1.1.9 and later | |
| Title | QcalAgent | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2026-09-18T14:31:44.541Z
Reserved: 2024-02-20T09:36:58.211Z
Link: CVE-2024-27123
Updated: 2026-09-18T14:30:04.727Z
Status : Deferred
Published: 2026-09-18T07:16:48.117
Modified: 2026-09-18T19:29:56.010
Link: CVE-2024-27123
No data.
OpenCVE Enrichment
Updated: 2026-09-19T22:30:30Z