Junglewise Threat Intelligence

CVE-2022-49036: Synology Active Backup for Business code execution in OpenSSL configuration

CVE-2022-49036 · Severity: high · CVSS 7.8 · Published 2026-06-03

Vendors: Synology.

Executive brief

Synology Active Backup for Business Recovery Media Creator is a tool used to create bootable media for restoring entire systems from backups. A security vulnerability in how this tool handles its internal configuration allows a local user with basic access to the system to execute unauthorized commands. This could lead to a full system takeover, data theft, or the permanent disruption of recovery operations.

Technical details

A vulnerability classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere) exists in the OpenSSL configuration handling of Synology Active Backup for Business Recovery Media Creator. The flaw allows a local user with low privileges to influence the application's execution environment or configuration files to load malicious code or libraries. Successful exploitation enables arbitrary code execution with the privileges of the application, potentially leading to local privilege escalation. The issue is resolved in version 2.5.0-2081 and later.

Affected products

  • Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081

Timeline

  • 2026-06-03: advisory: NVD publication date
  • 2026-06-03: disclosed: Synology advisory release

References