Description
An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Exposure via SQL Injection
Action: Patch
AI Analysis

Impact

The vulnerability is an SQL injection in the Sharing API of Synology DiskStation Manager, where special characters are not properly neutralized in SQL commands. Attackers who are authenticated can craft API requests that cause the backend database to return the contents of any file that is shared, effectively allowing them to read arbitrary files on the device. The weakness is a classic input handling flaw (CWE‑89).

Affected Systems

Synology DiskStation Manager installations running any of the versions listed as vulnerable: any pre‑7.2.1 builds before build 69057‑10, any 7.2.2 builds before build 72806‑7, and any 7.3.2 builds before build 86009‑2. All affected DSM deployments using the standard Sharing API are implicated.

Risk and Exploitability

The CVSS score of 6.5 reflects a moderate impact focused on data confidentiality. The EPSS score indicates a very low probability of exploitation at present, and the vulnerability is not currently listed in CISA’s KEV catalog. Exploitation still requires the attacker to be an authenticated user, but once authenticated, they can retrieve arbitrary files through simple API calls, making the attack straightforward for privileged users or attackers who have compromised credentials. Overall, the risk is moderate, with a clear path to data exposure rather than code execution or denial of service.

Generated by OpenCVE AI on September 19, 2026 at 20:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update DiskStation Manager to a version where the patch is applied (any release after the listed vulnerable builds).
  • Restrict or disable the Sharing API for users who do not need it, ensuring the principle of least privilege is enforced.
  • Enable logging of API access and review file access patterns for anomalies that could indicate exploitation.

Generated by OpenCVE AI on September 19, 2026 at 20:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title SQL Injection in Synology DiskStation Manager Sharing API Allows Remote Authenticated Users to Access Arbitrary Files

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title SQL Injection in Synology DiskStation Manager Sharing API Allows Remote Authenticated Users to Access Arbitrary Files

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain arbitrary sharing files.
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T19:10:31.286Z

Reserved: 2026-03-12T04:29:18.730Z

Link: CVE-2026-4036

cve-icon Vulnrichment

Updated: 2026-09-18T19:10:22.554Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:41.547

Modified: 2026-09-18T20:17:16.103

Link: CVE-2026-4036

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')