Junglewise Threat Intelligence

CVE-2026-40530: Synology DiskStation Manager CRLF injection in User API

CVE-2026-40530 · Severity: high · CVSS 8 · Published 2026-09-18

Technologies: Synology DiskStation Manager. Vendors: Synology.

Executive brief

DiskStation Manager (DSM) is a web-based operating system that manages Synology NAS devices and controls file sharing, user access, and system operations. A CRLF injection vulnerability in the User API allows authenticated users to read or write arbitrary files and cause denial-of-service attacks after system reboot, potentially compromising data integrity and system availability.

Technical details

The vulnerability is an improper neutralization of CRLF sequences (CWE-93) in the User API component of Synology DSM. The flaw allows remote authenticated users to inject carriage return and line feed characters to manipulate system behavior, enabling arbitrary file read/write and denial-of-service attacks that persist after system reboot. The attack requires authentication and user interaction (per CVSS vector: AV:N/AC:L/PR:L/UI:R). The vulnerability has been patched in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2 or later versions.

Affected products

  • Synology DiskStation Manager before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2

Timeline

  • 2026-04-15: disclosed: Synology advisory SA_26_06 published
  • 2026-09-18: patched: Patches available in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2
  • 2026-09-18: advisory

References

Related threats