Junglewise Threat Intelligence

CVE-2026-4036: Synology DiskStation Manager SQL injection in Sharing API

CVE-2026-4036 · Severity: medium · CVSS 6.5 · Published 2026-09-18

Technologies: Synology DiskStation Manager (DSM). Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM) is a network-attached storage operating system widely used in organizations for data storage and backup. A SQL injection flaw in the Sharing API allows authenticated users to extract arbitrary files shared on the system, potentially exposing sensitive documents, photos, and other data stored on affected devices without requiring user interaction or special privileges.

Technical details

A SQL injection (CWE-89) vulnerability exists in the Sharing API component of Synology DSM due to improper neutralization of special characters in SQL commands. The vulnerability is network-accessible and requires authenticated access (PR:L), but no user interaction is needed. An attacker with valid credentials can craft malicious SQL queries through the Sharing API to read arbitrary shared files from the system. The flaw affects DSM versions before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2, all of which have received patches addressing this issue.

Affected products

  • Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2

Timeline

  • 2026-04-15: disclosed
  • 2026-09-18: patched

References

Related threats