Junglewise Threat Intelligence

CVE-2026-40536: Synology DiskStation Manager path traversal in Audio API

CVE-2026-40536 · Severity: medium · CVSS 4.3 · Published 2026-09-18

Technologies: Synology DiskStation Manager. Vendors: Synology.

Executive brief

Synology DiskStation Manager (DSM) is a network storage operating system used to manage and access files on Synology NAS devices. A path traversal vulnerability in the Audio API allows authenticated users to read non-sensitive files beyond their intended access boundaries, potentially exposing system information or configuration details that could aid further attacks.

Technical details

CVE-2026-40536 is a path traversal vulnerability (CWE-22) in the Audio API of Synology DiskStation Manager that allows authenticated users to bypass directory restrictions and read files outside the intended scope. The vulnerability requires authentication and network access (CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N). An authenticated attacker can exploit this to obtain non-sensitive information by crafting specially-crafted requests with path traversal sequences. Synology has released patches addressing this vulnerability in DSM 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2 or later.

Affected products

  • Synology DiskStation Manager before 7.2.1-69057-10, 7.2.2-72806-7, and 7.3.2-86009-2

Timeline

  • 2026-04-15: disclosed
  • 2026-04-15: patched: Patches released for DSM 7.2.1, 7.2.2, and 7.3
  • 2026-09-18: other: CVE-2026-40536 published on NVD

References

Related threats