Executive brief
Synology DiskStation Manager (DSM) is a network storage operating system used to manage and access files on Synology NAS devices. A path traversal vulnerability in the Audio API allows authenticated users to read non-sensitive files beyond their intended access boundaries, potentially exposing system information or configuration details that could aid further attacks.
Technical details
CVE-2026-40536 is a path traversal vulnerability (CWE-22) in the Audio API of Synology DiskStation Manager that allows authenticated users to bypass directory restrictions and read files outside the intended scope. The vulnerability requires authentication and network access (CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). An authenticated attacker can exploit this to obtain non-sensitive information by crafting specially-crafted requests with path traversal sequences. Synology has released patches addressing this vulnerability in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2 or later.
Affected products
- Synology DiskStation Manager before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2
Timeline
- 2026-04-15: disclosed
- 2026-04-15: patched: Patches released for DSM 7.2.1, 7.2.2, and 7.3
- 2026-09-18: other: CVE-2026-40536 published on NVD