Executive brief
Synology DiskStation Manager (DSM) is network-attached storage (NAS) management software used to administer file storage and backup systems. An authentication bypass flaw in the LDAP API allows logged-in users to read or write arbitrary files on the NAS and cause service outages, potentially exposing sensitive business data or rendering critical storage infrastructure unavailable.
Technical details
CVE-2026-13673 is an incorrect permission assignment vulnerability (CWE-732) in the LDAP API component of Synology DSM. The flaw allows remote authenticated users to bypass access controls and read or write arbitrary files on the system, as well as conduct denial-of-service attacks. The vulnerability is network-reachable and requires valid login credentials, but no additional user interaction. Affected versions include DSM 7.2.1 before 69057-12, 7.2.2 before 72806-9, 7.3.2 before 86009-4, and 7.4 before 90075. Patches are available for all affected branches.
Affected products
- Synology DiskStation Manager (DSM) 7.2.1 before 69057-12, 7.2.2 before 72806-9, 7.3.2 before 86009-4, 7.4 before 90075
Timeline
- 2026-09-18: disclosed: CVE-2026-13673 published; patches available
- 2026-09-18: patched: Synology released security updates for DSM 7.2.1, 7.2.2, 7.3.2, and 7.4