Junglewise Threat Intelligence

CVE-2026-13635: Synology DiskStation Manager improper encoding in Auth API

CVE-2026-13635 · Severity: medium · CVSS 5.3 · Published 2026-09-18

Technologies: Synology DiskStation Manager. Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM) is a control system for network-attached storage devices. A vulnerability in its authentication API allows remote attackers without valid credentials to obtain non-sensitive information through improper output encoding, potentially exposing system details that could aid further attacks.

Technical details

CVE-2026-13635 is an improper encoding or escaping of output vulnerability (CWE-116) in the Auth API component of Synology DSM. The vulnerability is remotely exploitable without authentication or user interaction (CVSS vector AV:N/AC:L/PR:N/UI:N). By crafting specific requests to the Auth API, attackers can bypass output encoding protections and extract non-sensitive information about the system. The issue affects DSM versions before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075. Patches are available for all affected versions.

Affected products

  • Synology DiskStation Manager before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: Updates available: DSM 7.2.1-69057-12 or above, 7.2.2-72806-9 or above, 7.3.2-86009-4 or above, 7.4-90075 or above

References

Related threats