Description
An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks.
Published: 2026-09-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote File Write
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an external control of file name or path in the Upload API of Synology DiskStation Manager. Remote authenticated users can specify arbitrary file names or paths and write files to the system. They may create or overwrite any file that the DSM process can access, leading to denial of service by corrupting critical system files.

Affected Systems

Synology DiskStation Manager devices running firmware versions before DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 or 7.4-90075 are vulnerable. Any Synology NAS operating those firmware releases is affected.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% reflects a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. Attackers must be authenticated to the DSM system; therefore, the likely attack vector involves a compromised or malicious legitimate user account. Once authenticated, the attacker can exploit the upload feature to write arbitrary files and cause a denial‑of‑service by corrupting essential system files.

Generated by OpenCVE AI on September 19, 2026 at 20:12 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Synology DiskStation Manager to at least DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, or 7.4-90075, or to any later firmware that includes the patch.
  • Restrict use of the Upload API to users who require it by adjusting DSM user permissions or disabling upload functionality for users who do not need it.
  • Limit external access to the Upload API by configuring firewall rules or network segmentation so that only trusted internal networks or services can reach ports 5000/5001.

Generated by OpenCVE AI on September 19, 2026 at 20:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Synology
Synology diskstation Manager
Vendors & Products Synology
Synology diskstation Manager

Sat, 19 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title External File Path Injection in Synology DiskStation Manager Upload API

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks.
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Synology Diskstation Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: synology

Published:

Updated: 2026-09-18T19:57:02.255Z

Reserved: 2026-04-13T10:51:07.187Z

Link: CVE-2026-6205

cve-icon Vulnrichment

Updated: 2026-09-18T19:56:58.036Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T09:16:42.133

Modified: 2026-09-18T20:17:21.250

Link: CVE-2026-6205

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:15:05Z

Weaknesses
  • CWE-73

    External Control of File Name or Path