Junglewise Threat Intelligence

CVE-2025-13593: Synology ActiveProtect Agent origin validation error in installer

CVE-2025-13593 · Severity: medium · CVSS 6.1 · Published 2026-05-27

Vendors: Synology.

Executive brief

Synology ActiveProtect Agent is a backup and recovery tool used to protect business data. A security flaw in the Windows version of this software could allow a local user to create or overwrite files on the system during the installation process. This could lead to system instability or a denial of service, potentially disrupting backup operations.

Technical details

An origin validation error (CWE-346) exists in the Synology ActiveProtect Agent for Windows during the installation phase. The vulnerability allows a local attacker to perform arbitrary file writes, though the content of these files is restricted. The attack requires user interaction and is executed locally. Successful exploitation can lead to high availability impact, such as system crashes or service disruption, and low integrity impact. The issue is resolved in ActiveProtect Agent version 1.1.0-0439.

Affected products

  • Synology ActiveProtect Agent before 1.1.0-0439

Timeline

  • 2025-11-24: advisory: Initial public release of advisory Synology-SA-25:15
  • 2026-05-27: disclosed: Vulnerability details and CVE-2025-13593 disclosed
  • 2026-05-27: patched: Fixed in version 1.1.0-0439

References