Junglewise Threat Intelligence

CVE-2026-3091: Synology Presto Client uncontrolled search path in installer

CVE-2026-3091 · Severity: medium · CVSS 6.7 · Published 2026-02-24

Vendors: Synology.

Executive brief

Synology Presto Client is a desktop application used for high-speed file transfers to Synology NAS devices. A security flaw in the Windows installer allows a local attacker to gain unauthorized control over the system by placing a malicious file in the same folder as the installer before it is run. This could lead to the theft of sensitive data, modification of system files, or a complete system crash.

Technical details

An uncontrolled search path element vulnerability (CWE-427) exists in the Synology Presto Client installer for Windows. The vulnerability is triggered when the installer attempts to load DLL dependencies from its current working directory without proper validation. A local attacker with low privileges can exploit this by placing a malicious DLL in the same directory as the installer executable. If a user subsequently runs the installer, the malicious code is executed with the privileges of the installer, potentially allowing for arbitrary file read/write operations or a denial-of-service. This issue is resolved in version 2.1.3-0672.

Affected products

  • Synology Presto Client before 2.1.3-0672

Timeline

  • 2026-02-24: disclosed
  • 2026-02-24: patched: Fixed in version 2.1.3-0672
  • 2026-02-24: advisory

References