Description
An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Access and Denial of Service
Action: Immediate Patch
AI Analysis

Impact

An incorrect permission assignment in the LDAP API of Synology DiskStation Manager permits remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks. The flaw allows attackers to manipulate critical system resources, potentially compromising confidentiality, integrity, and availability of the device due to improper access control.

Affected Systems

The vulnerability affects Synology DiskStation Manager versions before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075. Devices running any of these releases are at risk if the LDAP API is enabled.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity risk. The EPSS score of less than 1% suggests a low exploitation probability at the time of this analysis, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access; however, once authenticated, attackers can read or modify files, which may lead to compromise or service disruption.

Generated by OpenCVE AI on September 19, 2026 at 20:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Synology DiskStation Manager to a version that includes the CVE fix (versions 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, 7.4-90075 or later).
  • If an upgrade is not immediately feasible, restrict LDAP API access to trusted networks and enforce stricter permission controls to limit file read/write capabilities.
  • Disable the LDAP API entirely if it is not required for your environment to eliminate the attack surface.

Generated by OpenCVE AI on September 19, 2026 at 20:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title LDAP API Permission Assignment Vulnerability Allowing Remote File Access and Denial of Service

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title LDAP API Permission Assignment Vulnerability Allowing Remote File Access and Denial of Service

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An incorrect permission assignment for critical resource vulnerability in LDAP API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks.
Weaknesses CWE-732
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T19:12:15.838Z

Reserved: 2026-06-29T10:36:23.989Z

Link: CVE-2026-13673

cve-icon Vulnrichment

Updated: 2026-09-18T19:12:12.635Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:38.997

Modified: 2026-09-18T20:17:07.867

Link: CVE-2026-13673

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-732

    Incorrect Permission Assignment for Critical Resource