Description
An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information disclosure
Action: Update DSM
AI Analysis

Impact

An attacker able to interact with the Desktop API in Synology DiskStation Manager may retrieve non‑sensitive internal data. The vulnerability, known as an exposure of sensitive information through data queries, can allow a remote attacker to obtain information that is not explicitly protected but is still valuable. The impact is limited to confidentiality; there is no direct mention of integrity or availability effects.

Affected Systems

Synology DiskStation Manager (DSM) versions prior to 7.2.1‑69057‑10, 7.2.2‑72806‑7 and 7.3.2‑86009‑2 are affected. All supported DSM releases with these version numbers before the listed updates are potentially vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk level, and the EPSS of less than 1% shows that exploitation is unlikely at present. The vulnerability is not listed in CISA’s KEV catalog, further suggesting that no widespread attacks have been observed. The likely attack vector is remote network access to the Desktop API; an attacker would need network reach to the DSM device and the ability to send API queries to exploit this flaw.

Generated by OpenCVE AI on September 19, 2026 at 20:03 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Synology DSM to a fixed version: 7.2.1‑69057‑10 or newer, 7.2.2‑72806‑7 or newer, or 7.3.2‑86009‑2 or newer.
  • If an update cannot be applied immediately, restrict external access to the Desktop API by disabling the feature or blocking its port in the DSM firewall settings.
  • Regularly review DSM logs for unexpected API activity and enforce strict authentication when the Desktop API is enabled.

Generated by OpenCVE AI on September 19, 2026 at 20:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Title Sensitive Information Exposure via Desktop API Queries in Synology DiskStation Manager

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Sensitive Information Exposure via Desktop API Queries in Synology DiskStation Manager

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to obtain non-sensitive information.
Weaknesses CWE-202
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T10:43:54.188Z

Reserved: 2026-04-14T01:01:14.606Z

Link: CVE-2026-40533

cve-icon Vulnrichment

Updated: 2026-09-18T10:43:45.834Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:40.627

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-40533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-202

    Exposure of Sensitive Information Through Data Queries