Description
An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
Published: 2026-08-03
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from incorrect default permissions in Synology Assistant, allowing any local user to read or write arbitrary files on the device. This leads to potential data confidentiality breaches and integrity violations, while also enabling denial-of-service during the installation process. The flaw is a direct consequence of misconfigured access controls, as identified by CWE-276.

Affected Systems

Synology Assistant versions prior to 7.0.7-50095 are affected. Administrators should verify the current version of Synology Assistant and confirm whether an upgrade to at least 7.0.7-50095 has occurred.

Risk and Exploitability

The CVSS score of 7.3 classifies this flaw as high severity, though the EPSS score is not available and the vulnerability is not listed in CISA KEV. The attack vector is local; an attacker must have local user access to the device. No remote exploitation has been documented, and the vulnerability can be mitigated by applying the released patch. Given the local nature, the risk largely depends on the likelihood of local user compromise.

Generated by OpenCVE AI on August 3, 2026 at 08:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch or upgrade Synology Assistant to version 7.0.7-50095 or later.
  • Ensure that user accounts have the principle of least privilege and avoid granting unnecessary local access.
  • Verify that the permissions on all critical system files and directories are correctly set and that no residual insecure defaults remain after the update.

Generated by OpenCVE AI on August 3, 2026 at 08:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
CPEs cpe:2.3:a:synology:assistant:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows

Mon, 03 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology assistant
Vendors & Products Synology
Synology assistant

Mon, 03 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Title Local Permissions Misconfiguration Enabling Arbitrary File Read/Write and Installation Denial in Synology Assistant

Mon, 03 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Microsoft Windows
Synology Assistant
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-08-03T14:54:10.232Z

Reserved: 2026-03-25T00:47:20.775Z

Link: CVE-2026-4793

cve-icon Vulnrichment

Updated: 2026-08-03T14:54:05.967Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T07:16:43.453

Modified: 2026-08-21T16:23:17.737

Link: CVE-2026-4793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:00:15Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions