Executive brief
Synology DiskStation Manager (DSM) is the operating system that powers Synology NAS storage devices, widely used by businesses and individuals for data backup and file sharing. A path traversal vulnerability in the Desktop API allows unauthenticated attackers to write limited files and cause service disruptions, potentially compromising data integrity and system availability on affected NAS devices.
Technical details
CVE-2026-40535 is a path traversal (CWE-22) vulnerability in the Desktop API component of Synology DSM. The vulnerability allows remote attackers without authentication (PR:N) to write limited files and conduct limited denial-of-service attacks via specially crafted requests over the network (AV:N, AC:L). The attack requires no user interaction and affects the integrity and availability of the system. Patches are available in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2 or later.
Affected products
- Synology DiskStation Manager before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2
Timeline
- 2026-04-15: disclosed
- 2026-04-15: patched: Patches released: DSM 7.2.1-69057-10, 7.2.2-72806-7, 7.3.2-86009-2
- 2026-09-18: advisory