Executive brief
Synology DiskStation Manager (DSM) is the operating system that manages Synology NAS (Network Attached Storage) devices, which are used to store and protect business-critical data. A SQL injection vulnerability in the EventScheduler API allows administrators with elevated privileges to query the database and extract non-sensitive information, potentially exposing system configuration details or operational data that could be leveraged in further attacks.
Technical details
CVE-2026-13683 is a SQL injection vulnerability in the EventScheduler API component of Synology DSM, caused by improper neutralization of special SQL command elements in user input. The vulnerability is network-accessible and requires authentication with administrator privileges, and the attacker must have UI disabled (PR:H indicates high privilege requirement). An authenticated administrator can craft malicious SQL queries through the EventScheduler API to read non-sensitive information from the database. The vulnerability is fixed in DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075 or above.
Affected products
- Synology DiskStation Manager before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075
Timeline
- 2026-09-18: disclosed
- 2026-09-18: patched