CVE-2023-32976: QNAP Container Station

High severity, CVSS 7.2. EPSS: 1.1% chance of exploitation in the next 30 days.

An OS command injection vulnerability has been reported to affect Container Station. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following version: Container Station 2.6.7.44 and later

Affected products

  • QNAP Container Station: before 2.6.7.44 (fixed in 2.6.7.44)

Published 2023-10-13. Last modified 2026-06-17.