PT-2026-83027 · Synology · Synology Chat Server

·

CVE-2026-9548

·

Published

2026-08-28

·

Updated

2026-08-29

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Synology Chat Server versions prior to 2.4.5-22148
Description An improper neutralization of input during web page generation, known as Cross-site Scripting (XSS), occurs in the extract domain component. This allows remote authenticated users to read or write restricted files and perform limited denial-of-service attacks in DSM through UI interaction.
Recommendations Update Synology Chat Server to version 2.4.5-22148 or later.

Fix

DoS

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9548

Affected Products

Synology Chat Server