Junglewise Threat Intelligence

CVE-2026-13623: Synology DiskStation Manager cross-site scripting in Theme API

CVE-2026-13623 · Severity: medium · CVSS 4.8 · Published 2026-09-18

Technologies: Synology DiskStation Manager. Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM) is a centralized operating system for Synology NAS devices that manages file storage, backups, and security. A cross-site scripting (XSS) vulnerability in the Theme API allows authenticated administrators to execute malicious scripts in the browser context, potentially enabling them to read or write limited files on the NAS system. While exploitation requires administrator privileges and user interaction, successful attacks could compromise file integrity or expose sensitive data.

Technical details

CVE-2026-13623 is a stored or reflected cross-site scripting (CWE-79) vulnerability in the Theme API component of Synology DSM, caused by improper neutralization of untrusted input during web page generation. The vulnerability requires the attacker to be an authenticated user with administrator privileges, and exploitation may require tricking a victim into clicking a malicious link (indicated by the UI:R parameter in the CVSS vector). A successful exploit allows limited file read/write operations on the NAS device. The vulnerability affects DSM versions before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075; patches are available in those versions and above.

Affected products

  • Synology DiskStation Manager before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075

Timeline

  • 2026-09-18: disclosed

References

Related threats