Description
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to obtain non-sensitive information.
Published: 2026-09-18
Score: 2.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The EventScheduler API in Synology DiskStation Manager is vulnerable to SQL injection because user input is not properly escaped. An authenticated user with administrator privileges can send a crafted request to the API and cause arbitrary SQL statements to be executed, resulting in the exposure of non‑sensitive database information. This weakness is identified as CWE‑89.

Affected Systems

Synology DiskStation Manager versions prior to 7.2.1‑69057‑12, 7.2.2‑72806‑9, 7.3.2‑86009‑4 and 7.4‑90075 are affected. Administrators of these DSM installations are at risk if the EventScheduler API remains enabled.

Risk and Exploitability

The CVSS score of 2.7 categorizes the vulnerability as low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the attack requires remote access to the DSM with administrator credentials, the risk is limited to environments where an attacker can obtain or guess such credentials. The impact of a successful exploitation is the disclosure of non‑sensitive data available to the authenticated administrator.

Generated by OpenCVE AI on September 19, 2026 at 21:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Synology DSM to a version that contains the patch for the EventScheduler SQL injection, such as DSM 7.2.1‑69057‑12 or newer, 7.2.2‑72806‑9 or newer, 7.3.2‑86009‑4 or newer, or 7.4‑90075 or newer as listed in the vendor advisory.
  • Restrict or disable the EventScheduler API for accounts that do not require it, limiting the attack surface to only the essential administrative users.
  • Configure logging and monitor API calls to detect suspicious SQL queries or repeated use of the EventScheduler endpoint, allowing prompt investigation of anomalous activity.

Generated by OpenCVE AI on September 19, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title SQL Injection in Synology DSM EventScheduler API Allows Admin Access to Non‑sensitive Data

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in Synology DSM EventScheduler API Allows Admin Access to Non‑sensitive Data

Fri, 18 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to obtain non-sensitive information.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T11:25:20.671Z

Reserved: 2026-06-29T10:41:59.800Z

Link: CVE-2026-13683

cve-icon Vulnrichment

Updated: 2026-09-18T11:25:12.802Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:39.117

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-13683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')