Junglewise Threat Intelligence

CVE-2024-47263: Synology Hyper Backup path traversal in Backup.Repository webapi

CVE-2024-47263 · Severity: medium · CVSS 4.1 · Published 2026-06-03

Vendors: Synology.

Executive brief

Synology Hyper Backup, a tool used for backing up data on Synology NAS devices, contains a security flaw that allows an administrator to write files outside of intended folders. While this requires administrative access, it could allow a user to bypass certain directory restrictions to place non-sensitive files in unauthorized locations. This could lead to minor data integrity issues or organizational policy violations.

Technical details

A path traversal vulnerability (CWE-22) exists in the Backup.Repository webapi component of Synology Hyper Backup. The flaw stems from improper limitation of pathnames, allowing a remote authenticated user with administrator privileges to bypass directory restrictions. An attacker can exploit this via unspecified vectors to write specific files containing non-sensitive information to locations outside the intended backup repository. The issue is resolved in Hyper Backup version 4.1.2-4036 and later.

Affected products

  • Synology Hyper Backup before 4.1.2-4036

Timeline

  • 2026-06-03: disclosed
  • 2026-06-03: advisory

References

Related threats