Description
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to read or write limited files.
Published: 2026-09-18
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

Based on the description, an improper neutralization of input during web page generation (CWE‑79) in Synology DiskStation Manager's Theme API can allow a remote authenticated administrator to inject malicious script content into pages served by the DSM interface. If successfully exploited, the attacker could execute arbitrary JavaScript within the context of the login session, potentially leading to cookie theft, credential compromise, or the ability to read and write a limited set of files exposed through DSM. The impact relies on the privilege level of the authenticated user and can lead to confidentiality and integrity issues.

Affected Systems

Synology DiskStation Manager (DSM) versions before 7.2.1‑69057‑12, 7.2.2‑72806‑9, 7.3.2‑86009‑4, and 7.4‑90075 are vulnerable. These include devices running DSM 7.x releases prior to the mentioned patch levels.

Risk and Exploitability

The CVSS score of 4.8 indicates a moderate risk, primarily due to the requirement of remote authentication with administrator privileges. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. However, because the flaw can be exploited via the Web UI, any exposed DSM instance with an administrative account remains a potential target. The attack vector is inferred to be remote, authenticated access to the Theme API through the DSM web interface, which would enable script injection.

Generated by OpenCVE AI on September 19, 2026 at 20:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Synology DSM update that addresses the Theme API XSS flaw
  • Restrict administrative access by disabling or limiting the use of admin accounts on the DSM web interface
  • If the Theme API is not required, disable it or prevent external calls to it to reduce exposure

Generated by OpenCVE AI on September 19, 2026 at 20:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in Synology DSM Theme API

Sat, 19 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Vulnerability in Synology DSM Theme API

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Theme API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to read or write limited files.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T11:28:39.237Z

Reserved: 2026-06-29T09:42:48.084Z

Link: CVE-2026-13623

cve-icon Vulnrichment

Updated: 2026-09-18T11:25:49.111Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:38.500

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-13623

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')