A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities.
We have already fixed the vulnerability in the following version:
Notification Center 1.10.0.3291 and later
We have already fixed the vulnerability in the following version:
Notification Center 1.10.0.3291 and later
Advisories
No advisories yet.
Fixes
Solution
We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.qnap.com/en/security-advisory/qsa-26-13 |
|
History
Wed, 10 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Qnap Systems
Qnap Systems notification Center |
|
| Vendors & Products |
Qnap Systems
Qnap Systems notification Center |
Wed, 10 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities. We have already fixed the vulnerability in the following version: Notification Center 1.10.0.3291 and later | |
| Title | Notification Center | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: qnap
Published:
Updated: 2026-06-10T01:38:27.401Z
Reserved: 2025-09-03T00:59:25.448Z
Link: CVE-2025-58468
No data.
Status : Received
Published: 2026-06-10T03:16:24.377
Modified: 2026-06-10T03:16:24.377
Link: CVE-2025-58468
No data.
OpenCVE Enrichment
Updated: 2026-06-10T11:21:23Z
Weaknesses