Junglewise Threat Intelligence

CVE-2026-13666: Synology DiskStation Manager CRLF injection in Sharing API

CVE-2026-13666 · Severity: low · CVSS 3.5 · Published 2026-09-18

Technologies: Synology DiskStation Manager. Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM) is the operating system for Synology NAS devices used by businesses and individuals to store and share data. A CRLF injection vulnerability in the Sharing API allows an authenticated attacker to inject malicious content into sharing URLs, enabling them to write limited files if a victim clicks a malicious sharing link. This could be exploited to modify shared files or redirect users to phishing sites.

Technical details

CVE-2026-13666 is a CRLF injection vulnerability (CWE-93) in the Sharing API component of Synology DSM. The vulnerability stems from improper neutralization of CRLF (carriage return/line feed) sequences in user-supplied input. An authenticated attacker can craft a malicious sharing URL containing CRLF sequences that, when clicked by a victim, allow the attacker to write limited files to the system. The attack requires user interaction (a victim must click the sharing URL) and authentication credentials. Patches are available for affected versions: upgrade to DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, or 7.4-90075 or later.

Affected products

  • Synology DiskStation Manager before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: patched: Fixed in DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075 or later

References

Related threats