Junglewise Threat Intelligence

CVE-2026-13673: Synology DiskStation Manager incorrect permission assignment in LDAP API

CVE-2026-13673 · Severity: high · CVSS 8.8 · Published 2026-09-18

Technologies: Synology DiskStation Manager (DSM). Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM) is network-attached storage (NAS) management software used to administer file storage and backup systems. An authentication bypass flaw in the LDAP API allows logged-in users to read or write arbitrary files on the NAS and cause service outages, potentially exposing sensitive business data or rendering critical storage infrastructure unavailable.

Technical details

CVE-2026-13673 is an incorrect permission assignment vulnerability (CWE-732) in the LDAP API component of Synology DSM. The flaw allows remote authenticated users to bypass access controls and read or write arbitrary files on the system, as well as conduct denial-of-service attacks. The vulnerability is network-reachable and requires valid login credentials, but no additional user interaction. Affected versions include DSM 7.2.1 before 69057-12, 7.2.2 before 72806-9, 7.3.2 before 86009-4, and 7.4 before 90075. Patches are available for all affected branches.

Affected products

  • Synology DiskStation Manager (DSM) 7.2.1 before 69057-12, 7.2.2 before 72806-9, 7.3.2 before 86009-4, 7.4 before 90075

Timeline

  • 2026-09-18: disclosed: CVE-2026-13673 published; patches available
  • 2026-09-18: patched: Synology released security updates for DSM 7.2.1, 7.2.2, 7.3.2, and 7.4

References

Related threats