PT-2026-95315 · Synology · Diskstation Manager

·

CVE-2026-13683

·

Published

2026-09-18

·

Updated

2026-09-18

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Synology DiskStation Manager (DSM) versions prior to 7.2.1-69057-12 Synology DiskStation Manager (DSM) versions prior to 7.2.2-72806-9 Synology DiskStation Manager (DSM) versions prior to 7.3.2-86009-4 Synology DiskStation Manager (DSM) versions prior to 7.4-90075
Description An SQL Injection issue exists in the EventScheduler API. This occurs due to improper neutralization of special elements used in an SQL command, allowing remote authenticated users with administrator privileges to obtain non-sensitive information.
Recommendations Update to version 7.2.1-69057-12 or later. Update to version 7.2.2-72806-9 or later. Update to version 7.3.2-86009-4 or later. Update to version 7.4-90075 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13683

Affected Products

Diskstation Manager