Executive brief
Synology DiskStation Manager (DSM) is a network-attached storage operating system used to manage data storage and sharing in enterprise and small business environments. This vulnerability allows remote attackers without authentication to obtain sensitive information through improper handling of data queries in the Desktop API component, potentially exposing system configuration or user data details.
Technical details
CVE-2026-40533 is an exposure of sensitive information through data queries vulnerability (CWE-202) in the Desktop API component of Synology DSM. The vulnerability allows unauthenticated remote attackers to obtain non-sensitive information via the network without any special preconditions. The flaw results from improper data filtering in API queries, enabling attackers to retrieve information they should not have access to. Patches are available in DSM 7.2.1-69057-10 or later, 7.2.2-72806-7 or later, and 7.3.2-86009-2 or later.
Affected products
- Synology DiskStation Manager before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2
Timeline
- 2026-09-18: disclosed: Published on NVD
- 2026-04-15: advisory: Synology security advisory SA_26_06 published
- 2026-04-15: patched: Fixed in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2