PT-2026-82877 · Synology · Synology Chat Server

·

CVE-2026-40541

·

Published

2026-08-28

·

Updated

2026-08-30

CVSS v3.1

9.0

Critical

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Synology Chat Server versions prior to 2.4.5-22148
Description An improper neutralization of input during web page generation, known as Cross-site Scripting (XSS), occurs in the extract domain component. This allows remote authenticated users, through UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM. This issue may also expose users to session theft, credential compromise, or unauthorized actions within the application.
Recommendations Update Synology Chat Server to version 2.4.5-22148 or later. Restrict access to administrative interfaces. Monitor for unusual login activity or suspicious chat content. Educate users to avoid clicking unexpected links or embedded content.

Fix

DoS

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40541

Affected Products

Synology Chat Server