Executive brief
Synology DiskStation Manager is a centralized storage and file management system used in Synology NAS devices. An improper encoding flaw in the SCGI component allows remote attackers without authentication to read or write arbitrary files on affected systems and cause service disruptions, potentially exposing sensitive data or enabling ransomware deployment.
Technical details
CVE-2026-13684 is an improper encoding or escaping of output vulnerability (CWE-116) in the SCGI (Simple Common Gateway Interface) handler of Synology DSM. The vulnerability is network-accessible and requires no authentication, user interaction, or special privileges. Remote attackers can exploit this flaw to read or write arbitrary files and conduct denial-of-service attacks. Patches are available for DSM 7.2.1, 7.2.2, 7.3.2, and 7.4 as specified in the advisory.
Affected products
- Synology DiskStation Manager 7.2.1 before 7.2.1-69057-12, 7.2.2 before 7.2.2-72806-9, 7.3.2 before 7.3.2-86009-4, 7.4 before 7.4-90075
Timeline
- 2026-09-18: disclosed: Vulnerability disclosed by Synology and published on NVD
- 2026-09-18: patched: Patches released for DSM 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075 or above