Junglewise Threat Intelligence

CVE-2026-40532: Synology DiskStation Manager forced browsing in Wallpaper Path

CVE-2026-40532 · Severity: medium · CVSS 6.5 · Published 2026-09-18

Technologies: Synology DiskStation Manager. Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM) is the operating system that powers Synology NAS devices used to store and manage data for businesses and individuals. A direct request vulnerability allows authenticated users to bypass access controls and view sensitive information they should not be able to access, potentially exposing private files and system data.

Technical details

This is a forced browsing (direct request) vulnerability classified as CWE-425 in the Wallpaper Path component of DSM. An authenticated network attacker can bypass authorization checks by directly requesting resources in the wallpaper path, gaining access to sensitive information without proper permission validation. The vulnerability affects DSM 7.2.1 before 7.2.1-69057-10, DSM 7.2.2 before 7.2.2-72806-7, and DSM 7.3.2 before 7.3.2-86009-2. Patches are available in the fixed releases listed above. No user interaction is required beyond authentication.

Affected products

  • Synology DiskStation Manager 7.2.1 before 7.2.1-69057-10, 7.2.2 before 7.2.2-72806-7, 7.3.2 before 7.3.2-86009-2

Timeline

  • 2026-04-15: disclosed
  • 2026-04-15: patched: Patches released for DSM 7.2.1, 7.2.2, and 7.3.2
  • 2026-09-18: advisory: CVE published on NVD

References

Related threats