Description
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
Published: 2026-05-27
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An origin validation error in Synology Assistant before version 7.0.6‑50085 allows local users to write arbitrary files with restricted content and trigger a denial‑of‑service during installation. The flaw bypasses expected origin checks, permitting unauthorized creation or modification of critical files. This can be used to alter system configuration, drop malicious payloads, or interrupt the installation process, affecting the local system and potentially the device as a whole.

Affected Systems

Synology Assistant running on Synology NAS devices, any release prior to 7.0.6‑50085. The vulnerability affects the assistant component that handles software installation and package deployment, and it requires a user with local administrative or installation privileges.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score of <1% (approximately 0.004%) shows a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, suggesting limited known exploitation. The attack vector is local; an adversary needs a legitimate local account and must trigger the installation routine. Because the flaw allows writing arbitrary files during installation, an attacker could inject malicious configuration or executable files that the Synology Assistant later processes, potentially leading to denial of service or elevation of privileges on the affected device.

Generated by OpenCVE AI on June 2, 2026 at 09:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Synology Assistant version 7.0.6‑50085 or newer to apply the vendor fix.
  • Restrict local user permissions so that only trusted administrators can perform software installations and system configuration changes.
  • Enable or enforce package signature verification to ensure that only signed, trusted installation packages are accepted by Synology Assistant.

Generated by OpenCVE AI on June 2, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 10:15:00 +0000

Type Values Removed Values Added
Title Local User Arbitrary File Write via Origin Validation Error in Synology Assistant

Tue, 02 Jun 2026 08:30:00 +0000

Type Values Removed Values Added
Description An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content during installation. An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

Mon, 01 Jun 2026 20:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:synology:assistant:*:*:*:*:*:*:*:*

Sat, 30 May 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology assistant
Vendors & Products Synology
Synology assistant

Wed, 27 May 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 27 May 2026 10:45:00 +0000

Type Values Removed Values Added
Title Local User Arbitrary File Write via Origin Validation Error in Synology Assistant

Wed, 27 May 2026 09:00:00 +0000

Type Values Removed Values Added
Description An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content during installation.
Weaknesses CWE-346
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

Synology Assistant
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-06-02T08:21:55.359Z

Reserved: 2025-12-05T03:19:16.761Z

Link: CVE-2025-66593

cve-icon Vulnrichment

Updated: 2026-05-27T12:14:26.762Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-27T09:16:27.760

Modified: 2026-06-02T16:09:02.013

Link: CVE-2025-66593

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T10:00:06Z

Weaknesses