Executive brief
Synology DiskStation Manager is a centralized management system for NAS devices that handles file storage, sharing, and email integration. The PersonMail API contains a server-side request forgery vulnerability that allows authenticated users to make unauthorized requests to internal systems, potentially exposing non-sensitive information and expanding attack surface within the network. Organizations running affected DSM versions should prioritize patching to prevent lateral movement and data exposure.
Technical details
This is a server-side request forgery (SSRF) vulnerability in the PersonMail API component of Synology DSM, classified as CWE-918. The vulnerability requires authentication (remote authenticated users) but does not require user interaction or special configuration, making it accessible to any user with valid credentials. An attacker can exploit this to make requests to internal services or resources from the server's perspective, obtaining non-sensitive information. The vulnerability affects DSM 7.2.1 before 69057-10, DSM 7.2.2 before 72806-7, and DSM 7.3.2 before 86009-2; patches are available and should be applied immediately.
Affected products
- Synology DiskStation Manager 7.2.1 before 69057-10, 7.2.2 before 72806-7, 7.3.2 before 86009-2
Timeline
- 2026-04-15: disclosed: Advisory published by Synology
- 2026-04-15: patched: Patches released: DSM 7.2.1-69057-10, 7.2.2-72806-7, 7.3.2-86009-2
- 2026-09-18: advisory: CVE-2026-40537 published to NVD