---
id: CVE-2025-58468
title: >-
  A cross-site request forgery (CSRF) vulnerability has been reported to affect
  Notification Center
summary: >-
  A cross-site request forgery (CSRF) vulnerability has been reported to affect
  Notification Center. The remote attackers can then exploit the vulnerability
  to gain privileges or hijack user identities.


  We have already fixed the vulnerabi…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-352
vendor: qnap
product: notification_center
affected:
  - 'notification_center >= 1.10.0, < 1.10.0.3291'
patched:
  - notification_center 1.10.0.3291
published: '2026-06-10'
updated: '2026-08-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-58468'
references:
  - url: 'https://www.qnap.com/en/security-advisory/qsa-26-13'
    label: security@qnapsecurity.com.tw
tags:
  - nvd
epss: 0.00156
epssPercentile: 0.03948
ingestedAt: '2026-08-06T13:59:38.543Z'
---

## Overview

A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities.

We have already fixed the vulnerability in the following version:
Notification Center 1.10.0.3291 and later

## Affected

- `notification_center >= 1.10.0, < 1.10.0.3291`

## Remediation

Upgrade past the affected range:

- `notification_center 1.10.0.3291`
