Junglewise Threat Intelligence

CVE-2026-13639: Synology DiskStation Manager insufficient entropy in login logic

CVE-2026-13639 · Severity: critical · CVSS 9.8 · Published 2026-09-18

Technologies: Synology DiskStation Manager. Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM) is a network storage operating system that manages file access and user authentication on NAS devices. An insufficient entropy flaw in the login logic allows remote attackers without credentials to read or write arbitrary files and disrupt service availability. This exposes sensitive data and enables attackers to compromise the entire NAS device.

Technical details

This vulnerability is a CWE-331 (Insufficient Entropy) flaw in DSM's login logic that allows remote attackers to bypass authentication without credentials. The weak entropy in login mechanisms enables an attacker to predict or brute-force authentication tokens or session identifiers. No user interaction or authentication is required; the attack is performed remotely over the network. Successful exploitation allows attackers to achieve confidentiality, integrity, and availability impacts: reading arbitrary files, modifying stored data, and denying service. Patches are available in DSM 7.2.1-69057-12 or later, 7.2.2-72806-9 or later, 7.3.2-86009-4 or later, and 7.4-90075 or later.

Affected products

  • Synology DiskStation Manager before 7.2.1-69057-12, 7.2.2 before 7.2.2-72806-9, 7.3 before 7.3.2-86009-4, 7.4 before 7.4-90075

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: Multiple patch releases published across DSM version branches

References

Related threats