Description
A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure by Remote Authenticated Users
Action: Apply Patch
AI Analysis

Impact

A forced browsing vulnerability in the Wallpaper Path component of Synology DiskStation Manager allows an attacker who has authenticated remotely to send a direct request to a sensitive endpoint and obtain information that should be protected. The flaw is a classic path traversal/forced browsing issue that can expose confidential data stored under the wallpaper directory. This weakness is classified as CWE-425, indicating that the system fails to enforce proper authorization checks on the resource path.

Affected Systems

Synology DiskStation Manager versions prior to 7.2.1‑69057‑10, 7.2.2‑72806‑7, and 7.3.2‑86009‑2 are vulnerable. The issue specifically impacts the wallpaper management interface exposed by DSM on networked devices from Synology.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, and the EPSS score of less than 1% shows a very low probability of exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog, suggesting limited or no evidence of active exploitation. Attackers would need valid DSM credentials to succeed, indicating that the threat surfaces only to authenticated users and relies on an authenticated session or credentials leakage.

Generated by OpenCVE AI on September 19, 2026 at 20:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Synology DSM to a patched version – 7.2.1‑69057‑10, 7.2.2‑72806‑7, or 7.3.2‑86009‑2 or newer, as described in the Synology advisory.
  • If immediate upgrade is not feasible, block or restrict remote access to the Wallpaper Path API endpoint (e.g., /webapi/...) using network firewall or DSM application firewall rules to prevent direct requests from unauthenticated or unauthorized users.
  • Once patched or blocked, verify that the Wallpaper Path resource is no longer accessible via forced browsing and that authentication checks remain enforced.

Generated by OpenCVE AI on September 19, 2026 at 20:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Forced Browsing Vulnerability Exposing Sensitive Data in Synology DSM Wallpaper Path

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Forced Browsing Vulnerability Exposing Sensitive Data in Synology DSM Wallpaper Path

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain sensitive information.
Weaknesses CWE-425
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T19:09:03.205Z

Reserved: 2026-04-14T01:01:14.606Z

Link: CVE-2026-40532

cve-icon Vulnrichment

Updated: 2026-09-18T19:08:58.970Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:40.473

Modified: 2026-09-18T20:17:15.857

Link: CVE-2026-40532

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')