---
id: CVE-2024-38639
title: An improper authentication vulnerability has been reported to affect product
summary: >-
  An improper authentication vulnerability has been reported to affect product.
  The remote attackers can then exploit the vulnerability to compromise the
  security of the system.

  QTS is not affected.


  We have already fixed the vulnerability…
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-287
vendor: QNAP Systems Inc.
product: QTS
affected:
  - QTS
published: '2026-09-18'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T19:29:56.010'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-38639'
references:
  - url: 'https://www.qnap.com/en/security-advisory/qsa-24-37'
    label: security@qnapsecurity.com.tw
tags:
  - nvd
  - cve.org
epss: 0.00246
epssPercentile: 0.14099
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-18T14:15:06.086803Z'
ingestedAt: '2026-09-18T07:37:23.429Z'
---

## Overview

An improper authentication vulnerability has been reported to affect product. The remote attackers can then exploit the vulnerability to compromise the security of the system.
QTS is not affected.

We have already fixed the vulnerability in the following version:

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
