PT-2026-95332 · Synology · Diskstation Manager

·

CVE-2026-6205

·

Published

2026-09-18

·

Updated

2026-09-19

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Synology DiskStation Manager versions prior to 7.2.1-69057-12 Synology DiskStation Manager versions prior to 7.2.2-72806-9 Synology DiskStation Manager versions prior to 7.3.2-86009-4 Synology DiskStation Manager versions prior to 7.4-90075
Description An external control of file name or path issue exists in the Upload API endpoint. This allows remote authenticated users to write arbitrary files to the system, which can lead to denial-of-service attacks.
Recommendations Update to version 7.2.1-69057-12 or later. Update to version 7.2.2-72806-9 or later. Update to version 7.3.2-86009-4 or later. Update to version 7.4-90075 or later.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6205

Affected Products

Diskstation Manager