Junglewise Threat Intelligence

CVE-2026-2237: Synology Storage Manager sensitive information disclosure in volume encryption

CVE-2026-2237 · Severity: medium · CVSS 6.2 · Published 2026-05-27

Vendors: Synology.

Executive brief

Synology Storage Manager, a tool used to manage data storage and encryption on Synology NAS devices, contains a security flaw in how it handles encrypted volumes. This vulnerability could allow a local user to see sensitive information, such as encryption keys or passwords, because the system transmits them in a way that can be recorded in system logs or browser history. An attacker with local access could use this information to gain unauthorized access to protected data.

Technical details

A vulnerability (CWE-598) exists in the volume encryption component of the Synology Storage Manager package before version 1.0.1-1100. The application uses the HTTP GET method to transmit sensitive data within query strings rather than using a more secure method like POST. Because GET parameters are frequently logged by web servers, proxies, and browser histories, a local attacker with access to these logs or the local environment can recover sensitive information related to volume encryption. This issue affects Storage Manager on DSM versions 7.2.1, 7.2.2, and 7.3. Users should update to version 1.0.1-1100 or later to resolve the issue.

Affected products

  • Synology Storage Manager for DSM 7.2.1 before 1.0.1-1100
  • Synology Storage Manager for DSM 7.2.2 before 1.0.1-1100
  • Synology Storage Manager for DSM 7.3 before 1.0.1-1100

Timeline

  • 2026-02-09: advisory: Initial public release of Synology advisory SA_26_01
  • 2026-05-27: disclosed: Vulnerability details and CVE-2026-2237 disclosed

References