CVE-2026-34007

QNAP Notes Station 3: Pre-Auth Remote Code Execution

An unauthenticated X-Forwarded-For header reaches shell_exec() through a broken IP-validation helper that returns the raw input instead of its sanitized fallback. Yields code execution as www-data inside the Notes Station 3 container with no user interaction.

Full advisory
CVE-2026-34008

QNAP Notes Station 3: Container Privilege Escalation and Host Escape

A www-data-writable crontab is installed by a root-owned monitor inside the container, and host home directories are bind-mounted writable with no user-namespace remapping. Chains from the pre-auth RCE to container root and then admin SSH on the NAS host.

Full advisory
0day

QNAP QmailAgent: Pre-Auth Time-Based Blind SQL Injection

Technical details are temporarily withheld.

Advisory locked

Disclosure

Coordinated by default

We report vulnerabilities to affected vendors and generally work to a 90-day disclosure timeline, extending it when patch development reasonably requires more time.

For vendor coordination or bounty communication, email research@runiclabs.io.