Junglewise Threat Intelligence

CVE-2026-40535: Synology DiskStation Manager path traversal in Desktop API

CVE-2026-40535 · Severity: medium · CVSS 6.5 · Published 2026-09-18

Technologies: Synology DiskStation Manager. Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM) is the operating system that powers Synology NAS storage devices, widely used by businesses and individuals for data backup and file sharing. A path traversal vulnerability in the Desktop API allows unauthenticated attackers to write limited files and cause service disruptions, potentially compromising data integrity and system availability on affected NAS devices.

Technical details

CVE-2026-40535 is a path traversal (CWE-22) vulnerability in the Desktop API component of Synology DSM. The vulnerability allows remote attackers without authentication (PR:N) to write limited files and conduct limited denial-of-service attacks via specially crafted requests over the network (AV:N, AC:L). The attack requires no user interaction and affects the integrity and availability of the system. Patches are available in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2 or later.

Affected products

  • Synology DiskStation Manager before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2

Timeline

  • 2026-04-15: disclosed
  • 2026-04-15: patched: Patches released: DSM 7.2.1-69057-10, 7.2.2-72806-7, 7.3.2-86009-2
  • 2026-09-18: advisory

References

Related threats