Description
An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks.
Published: 2026-09-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Read/Write arbitrary files and DoS via MITM
Action: Patch Now
AI Analysis

Impact

The vulnerability is an improper certificate validation flaw in DSM's Email API that allows attackers who can perform a man‑in‑the‑middle between the API client and server to read and write arbitrary files on the device. This flaw also enables denial‑of‑service by forging certificate errors to terminate API functions. The weakness aligns with CWE‑295, improper handling of security certificates.

Affected Systems

Affected products include Synology DiskStation Manager (DSM) for versions before 7.2.1‑69057‑10, 7.2.2‑72806‑7 and 7.3.2‑86009‑2. Any device running these releases that exposes the Email API to external networks is vulnerable. The documentation does not specify additional variant or edition, so all standard DSM distributions are impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates moderate to high severity, while the EPSS score of less than 1% suggests low exploitation probability so far. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it by intercepting traffic to the Email API, which requires network access to the DSM appliance and the ability to inject a rogue certificate. Consequently, the risk is noticeable for exposed systems, but the likelihood is currently low.

Generated by OpenCVE AI on September 19, 2026 at 20:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Synology DSM to 7.2.1‑69057‑10, 7.2.2‑72806‑7, 7.3.2‑86009‑2 or later.
  • Disable or restrict access to the Email API to trusted IP addresses or networks until the patch is applied.
  • Ensure only valid certificates are used by the Email API and remove any self‑signed certificates.

Generated by OpenCVE AI on September 19, 2026 at 20:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Synology DSM Email API Enables Remote File Access and DoS

Sat, 19 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Improper Certificate Validation in Synology DSM Email API Enables Remote File Access and DoS

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows man-in-the-middle attackers to read or write arbitrary files and conduct denial-of-service attacks.
Weaknesses CWE-295
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T10:40:16.842Z

Reserved: 2026-04-14T01:01:14.607Z

Link: CVE-2026-40539

cve-icon Vulnrichment

Updated: 2026-09-18T10:39:56.419Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:41.423

Modified: 2026-09-18T19:07:38.320

Link: CVE-2026-40539

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-295

    Improper Certificate Validation