Description
A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.
Published: 2026-09-18
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Assess Impact
AI Analysis

Impact

Synology DiskStation Manager contains a server‑side request forgery flaw in its PersonMail API that allows any user who can authenticate to the system to execute requests to internal or external resources and retrieve response data. The vulnerability does not grant arbitrary code execution or elevated privileges, but it can expose configuration data or other non‑sensitive information that should remain private. The weakness corresponds to the Common Weakness Enumeration 918, which describes messages sent from an application to a trusted server that could be redirected or manipulated by an attacker.

Affected Systems

The flaw is present in all Synology DSM releases prior to 7.2.1‑69057‑10, 7.2.2‑72806‑7, and 7.3.2‑86009‑2, meaning any DSM installation older than these specific revisions is vulnerable.

Risk and Exploitability

The official CVSS score is 4.3, placing the issue in the low‑to‑moderate range. The EPSS score is below 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack path requires that the attacker already possesses valid authenticated credentials against the DSM system; once authenticated, the SSRF can be triggered from the web interface without additional inputs, making the exploitation straightforward for insiders or attackers who have compromised a user account.

Generated by OpenCVE AI on September 19, 2026 at 20:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to DSM 7.2.1‑69057‑10 or later versions, or to DSM 7.2.2‑72806‑7 or DSM 7.3.2‑86009‑2 or later if using those branches.
  • Disable or restrict access to the PersonMail API by adjusting the DSM Access Control settings or network permissions so that only trusted users or IP addresses can invoke it.
  • Configure the DSM firewall or network segmentation to block outbound HTTP/HTTPS traffic from the device to untrusted internal or external resources, thereby preventing SSRF exploitation.

Generated by OpenCVE AI on September 19, 2026 at 20:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Title SSRF Vulnerability in Synology DSM PersonMail API Allows Authenticated Users to Access Non‑Sensitive Information

Sat, 19 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title SSRF Vulnerability in Synology DSM PersonMail API Allows Authenticated Users to Access Non‑Sensitive Information

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T10:47:34.328Z

Reserved: 2026-04-14T01:01:14.607Z

Link: CVE-2026-40537

cve-icon Vulnrichment

Updated: 2026-09-18T10:47:27.906Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:41.190

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-40537

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)