Synology · Diskstation Manager · CVE-2026-13666
**Name of the Vulnerable Software and Affected Versions**
Synology DiskStation Manager (DSM) versions prior to 7.2.1-69057-12
Synology DiskStation Manager (DSM) versions prior to 7.2.2-72806-9
Synology DiskStation Manager (DSM) versions prior to 7.3.2-86009-4
Synology DiskStation Manager (DSM) versions prior to 7.4-90075
**Description**
An improper neutralization of CRLF sequences, known as CRLF Injection, exists in the Sharing API. This issue allows remote authenticated users to write limited files if a victim clicks a sharing URL. CRLF Injection occurs when an application fails to properly filter Carriage Return (CR) and Line Feed (LF) characters, allowing an attacker to inject new lines into the HTTP response header.
**Recommendations**
Update to version 7.2.1-69057-12 or later.
Update to version 7.2.2-72806-9 or later.
Update to version 7.3.2-86009-4 or later.
Update to version 7.4-90075 or later.