Synology · Diskstation Manager · CVE-2026-6205
**Name of the Vulnerable Software and Affected Versions**
Synology DiskStation Manager versions prior to 7.2.1-69057-12
Synology DiskStation Manager versions prior to 7.2.2-72806-9
Synology DiskStation Manager versions prior to 7.3.2-86009-4
Synology DiskStation Manager versions prior to 7.4-90075
**Description**
An external control of file name or path issue exists in the Upload API endpoint. This allows remote authenticated users to write arbitrary files to the system, which can lead to denial-of-service attacks.
**Recommendations**
Update to version 7.2.1-69057-12 or later.
Update to version 7.2.2-72806-9 or later.
Update to version 7.3.2-86009-4 or later.
Update to version 7.4-90075 or later.