Description
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited denial-of-service attacks.
Published: 2026-09-18
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote file write and limited denial of service
Action: Patch Now
AI Analysis

Impact

The vulnerability is an improper restriction of a pathname to a designated directory (CWE‑22) in the Desktop API of Synology DiskStation Manager. Remote attackers can write files to controlled directories and trigger limited denial‑of‑service conditions by overwriting or creating specific files. The impact does not extend to full malicious code execution but permits manipulation of file contents and potential service disruption.

Affected Systems

Synology DiskStation Manager (DSM) is affected in all releases prior to version 7.2.1‑69057‑10, 7.2.2‑72806‑7 and 7.3.2‑86009‑2. Users running these earlier builds are at risk.

Risk and Exploitability

The CVSS score of 6.5 classifies the flaw as moderate severity, while the EPSS score of less than 1 % indicates a very low probability of exploitation. Synology has not listed the vulnerability in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote via the Desktop API over an open network interface. Exploitation requires network access to the DSM instance and the ability to construct a payload that includes a traversable path component. Successful exploitation allows limited file writes within the constrained directory, which could alter configuration files or trigger service failures, but does not grant full system compromise.

Generated by OpenCVE AI on September 19, 2026 at 20:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Synology DSM to a release that is newer than 7.2.1‑69057‑10, 7.2.2‑72806‑7 or 7.3.2‑86009‑2.
  • Restrict external access to the Desktop API by configuring firewall rules or disabling remote API features until a patch is applied.
  • Verify that directory permissions and sandboxes around the API enforce proper path validation to avoid traversal.

Generated by OpenCVE AI on September 19, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Path Traversal in Synology DSM Desktop API Allows Limited File Write and DoS

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in Synology DSM Desktop API Allows Limited File Write and DoS

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote attackers to write limited files and conduct limited denial-of-service attacks.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T10:43:26.294Z

Reserved: 2026-04-14T01:01:14.607Z

Link: CVE-2026-40535

cve-icon Vulnrichment

Updated: 2026-09-18T10:43:21.271Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:40.960

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-40535

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')