Junglewise Threat Intelligence

CVE-2026-9491: Synology Chat Server SSRF in webhook

CVE-2026-9491 · Severity: medium · CVSS 4.3 · Published 2026-08-28

Technologies: Synology Chat Server. Vendors: Synology.

Executive brief

Synology Chat Server contains a server-side request forgery vulnerability in its webhook functionality that allows authenticated users to access non-sensitive internal information. An attacker with valid credentials can exploit this to probe internal network resources and bypass security controls designed to restrict outbound requests.

Technical details

This is a server-side request forgery (SSRF) vulnerability (CWE-918) in the webhook component of Synology Chat Server prior to version 2.4.5-22148. The vulnerability requires authentication and network access but no user interaction. An authenticated remote attacker can manipulate webhook requests to access or retrieve non-sensitive information from internal systems that would normally be restricted. The vulnerability has been patched in version 2.4.5-22148 and later.

Affected products

  • Synology Chat Server before 2.4.5-22148

Timeline

  • 2026-05-26: disclosed: Initial public release of Synology-SA-26:10
  • 2026-08-28: disclosed: Vulnerability details disclosed
  • 2026-05-26: patched: Fixed in version 2.4.5-22148 or above

References

Related threats