Description
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched.
Published: 2026-09-18
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote XSS that allows authenticated users to read or write limited files via the Video API
Action: Immediate Patch
AI Analysis

Impact

A cross‑site scripting flaw is present in the Video API of Synology DiskStation Manager (DSM) before specific patched releases. The flaw arises from improper neutralization of user‑supplied input during web page generation, enabling an attacker to inject malicious script code. When exploited by a remote authenticated user, the script can read or write a restricted set of files on the NAS, giving the attacker partial data exfiltration or modification capability.

Affected Systems

Synology’s DiskStation Manager firmware versions prior to 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 are affected. These versions run on Synology NAS devices that provide the Video API web service. Users with local or network credentials that can start the video player are at risk.

Risk and Exploitability

The vulnerability has a CVSS score of 5.4, indicating a moderate severity. The EPSS score of less than 1% suggests exploitation is unlikely at present, and the issue is not listed in the CISA KEV catalog. The attack requires the attacker to be an authenticated user with permissions to launch the video player, so it is not a public unauthenticated vector but still poses significant risk in environments where many users have such privileges.

Generated by OpenCVE AI on September 19, 2026 at 20:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the NAS to DSM version 7.2.1-69057-10, 7.2.2-72806-7, or 7.3.2-86009-2 or any newer release that includes the fix
  • Revoke or limit the permissions of users who access the Video API, ensuring only essential accounts retain that capability
  • If an immediate upgrade is not feasible, temporarily disable the Video API feature or enforce firewall rules to block access to the associated endpoint until the patch is applied

Generated by OpenCVE AI on September 19, 2026 at 20:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title XSS in Synology DiskStation Manager Video API Allows Authenticated File Access

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title XSS in Synology DiskStation Manager Video API Allows Authenticated File Access

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write limited files when the player is launched.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T10:48:22.212Z

Reserved: 2026-04-14T01:01:14.606Z

Link: CVE-2026-40534

cve-icon Vulnrichment

Updated: 2026-09-18T10:48:17.007Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:40.840

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-40534

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')