Assessment
Why it matters
EPSS is 0.2%; technical severity is CVSS 7.0.
An external control of file name or path vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If an attacker gains local network access, they can then exploit the vulnerability to read or modify files or directories. We have already fixed the vulnerability in the following version: HBS 3 Hybrid Backup Sync 26.2.0.938 and later
Who should care
- Teams operating Hybrid Backup Sync
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Hybrid Backup Sync is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Vendor advisory from www.qnap.com
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Technical details
- CVSS vector
- CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CWE
- CWE-73
- Affected versions
- QNAP Hybrid Backup Sync (End Excluding 26.2.0.938)
- Fixed versions
- QNAP Hybrid Backup Sync (Fixed from 26.2.0.938)
- Published
- 2 January 2026
- Attack vector
- Physical
- Privileges required
- None
- User interaction
- None
Signal timeline
- CVE published
- Latest EPSS score: 0.2%
- Signal calculated at 11