Description
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

An improper limitation of a pathname to a restricted directory in the Audio API of Synology DiskStation Manager can allow a remote authenticated user to read non‑sensitive information from the server. The flaw is a classic path traversal weakness (CWE‑22) that does not provide escalation or malicious code execution, but it does expose data that should be protected from unauthenticated access.

Affected Systems

Synology DiskStation Manager (DSM) versions prior to 7.2.1‑69057‑10, 7.2.2‑72806‑7, and 7.3.2‑86009‑2 are affected. The vulnerability is located in the Audio API component of these firmware releases.

Risk and Exploitability

The CVSS score of 4.3 indicates a low to moderate severity; the EPSS score of less than 1% suggests a very low probability of real‑world exploitation. The flaw requires remote authentication, so an attacker must already have valid credentials, but the impact remains limited to non‑sensitive information disclosure. This vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on September 19, 2026 at 20:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Synology DSM to version 7.2.1‑69057‑10 or later, 7.2.2‑72806‑7 or later, or 7.3.2‑86009‑2 or later to receive the Audion API path‑traversal fix.
  • If an upgrade cannot be performed immediately, limit the credentials that have access to the Audio API by provisioning only trusted accounts and restricting other users’ privileges.
  • Alternatively, disable the Audio API feature or block its network access using firewall rules to prevent the traversal vector from being exercised.

Generated by OpenCVE AI on September 19, 2026 at 20:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in Synology DSM Audio API Allows Remote Authenticated Information Disclosure

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Path Traversal in Synology DSM Audio API Allows Remote Authenticated Information Disclosure

Fri, 18 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T11:51:29.563Z

Reserved: 2026-04-14T01:01:14.607Z

Link: CVE-2026-40536

cve-icon Vulnrichment

Updated: 2026-09-18T11:48:49.922Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:41.077

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-40536

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')