Executive brief
Synology Hyper Backup, a tool used for backing up data on Synology NAS devices, contains a security flaw that allows an administrator to write files outside of intended folders. While this requires administrative access, it could allow a user to bypass certain directory restrictions to place non-sensitive files in unauthorized locations. This could lead to minor data integrity issues or organizational policy violations.
Technical details
A path traversal vulnerability (CWE-22) exists in the Backup.Repository webapi component of Synology Hyper Backup. The flaw stems from improper limitation of pathnames, allowing a remote authenticated user with administrator privileges to bypass directory restrictions. An attacker can exploit this via unspecified vectors to write specific files containing non-sensitive information to locations outside the intended backup repository. The issue is resolved in Hyper Backup version 4.1.2-4036 and later.
Affected products
- Synology Hyper Backup before 4.1.2-4036
Timeline
- 2026-06-03: disclosed
- 2026-06-03: advisory