{"schema_version":1,"title":"Synology BeeDrive vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 6 vulnerabilities in Synology BeeDrive: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2024-11399, was published on 27 May 2026.","url":"https://junglewise.ai/threats/technologies/beedrive","json_url":"https://junglewise.ai/threats/technologies/beedrive.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/beedrive","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":6,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":6},"latest":[{"cve":"CVE-2024-11399","cvss":6.8,"slug":"cve-2024-11399-synology-beedrive-for-desktop-denial-of-service-in-redis-server","title":"Synology BeeDrive for desktop denial of service in redis-server","severity":"medium","exploited":false,"published_at":"2026-05-27T09:16:25.297+00:00","url":"https://junglewise.ai/threats/cve-2024-11399-synology-beedrive-for-desktop-denial-of-service-in-redis-server"},{"cve":"CVE-2023-52945","cvss":7.8,"slug":"cve-2023-52945-synology-beedrive-for-desktop-uncontrolled-search-path-in-openssl","title":"Synology BeeDrive for desktop uncontrolled search path in OpenSSL DLL","severity":"high","exploited":false,"published_at":"2026-05-27T09:16:24.777+00:00","url":"https://junglewise.ai/threats/cve-2023-52945-synology-beedrive-for-desktop-uncontrolled-search-path-in-openssl"},{"cve":"CVE-2025-8074","cvss":5.6,"epss":0.0009,"slug":"cve-2025-8074-origin-validation-error-vulnerability-in-beedrive-in-synology","title":"Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary","severity":"medium","exploited":false,"published_at":"2025-12-04T16:16:23.1+00:00","url":"https://junglewise.ai/threats/cve-2025-8074-origin-validation-error-vulnerability-in-beedrive-in-synology"},{"cve":"CVE-2025-54160","cvss":7.8,"epss":0.002,"slug":"cve-2025-54160-improper-limitation-of-a-pathname-to-a-restricted-directory-path","title":"Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop be","severity":"high","exploited":false,"published_at":"2025-12-04T16:16:21.343+00:00","url":"https://junglewise.ai/threats/cve-2025-54160-improper-limitation-of-a-pathname-to-a-restricted-directory-path"},{"cve":"CVE-2025-54159","cvss":7.5,"epss":0.0041,"slug":"cve-2025-54159-missing-authorization-vulnerability-in-beedrive-in-synology","title":"Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitr","severity":"high","exploited":false,"published_at":"2025-12-04T16:16:21.133+00:00","url":"https://junglewise.ai/threats/cve-2025-54159-missing-authorization-vulnerability-in-beedrive-in-synology"},{"cve":"CVE-2025-54158","cvss":7.8,"epss":0.0018,"slug":"cve-2025-54158-missing-authentication-for-critical-function-vulnerability-in","title":"Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local user","severity":"high","exploited":false,"published_at":"2025-12-04T16:16:20.923+00:00","url":"https://junglewise.ai/threats/cve-2025-54158-missing-authentication-for-critical-function-vulnerability-in"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"Synology DiskStation Manager","slug":"diskstation-manager","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/diskstation-manager"},{"name":"Synology Surveillance Station","slug":"surveillance-station","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/surveillance-station"},{"name":"Synology DiskStation Manager (DSM)","slug":"diskstation-manager-dsm","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/diskstation-manager-dsm"},{"name":"Synology Chat Server","slug":"chat-server","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/chat-server"}],"technology":{"hub":true,"name":"Synology BeeDrive","slug":"beedrive","vendor":{"name":"Synology","slug":"synology","url":"https://junglewise.ai/threats/vendors/synology"},"aliases":[],"category":"application","homepage":"https://bee.synology.com/en-us/beedrive","description":"A personal backup and storage management application for Synology BeeDrive hardware.","url":"https://junglewise.ai/threats/technologies/beedrive"},"most_severe":[{"cve":"CVE-2025-54160","cvss":7.8,"epss":0.002,"slug":"cve-2025-54160-improper-limitation-of-a-pathname-to-a-restricted-directory-path","title":"Improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in BeeDrive in Synology BeeDrive for desktop be","severity":"high","exploited":false,"published_at":"2025-12-04T16:16:21.343+00:00","url":"https://junglewise.ai/threats/cve-2025-54160-improper-limitation-of-a-pathname-to-a-restricted-directory-path"},{"cve":"CVE-2025-54158","cvss":7.8,"epss":0.0018,"slug":"cve-2025-54158-missing-authentication-for-critical-function-vulnerability-in","title":"Missing authentication for critical function vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows local user","severity":"high","exploited":false,"published_at":"2025-12-04T16:16:20.923+00:00","url":"https://junglewise.ai/threats/cve-2025-54158-missing-authentication-for-critical-function-vulnerability-in"},{"cve":"CVE-2023-52945","cvss":7.8,"slug":"cve-2023-52945-synology-beedrive-for-desktop-uncontrolled-search-path-in-openssl","title":"Synology BeeDrive for desktop uncontrolled search path in OpenSSL DLL","severity":"high","exploited":false,"published_at":"2026-05-27T09:16:24.777+00:00","url":"https://junglewise.ai/threats/cve-2023-52945-synology-beedrive-for-desktop-uncontrolled-search-path-in-openssl"},{"cve":"CVE-2025-54159","cvss":7.5,"epss":0.0041,"slug":"cve-2025-54159-missing-authorization-vulnerability-in-beedrive-in-synology","title":"Missing authorization vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.2-13960 allows remote attackers to delete arbitr","severity":"high","exploited":false,"published_at":"2025-12-04T16:16:21.133+00:00","url":"https://junglewise.ai/threats/cve-2025-54159-missing-authorization-vulnerability-in-beedrive-in-synology"},{"cve":"CVE-2024-11399","cvss":6.8,"slug":"cve-2024-11399-synology-beedrive-for-desktop-denial-of-service-in-redis-server","title":"Synology BeeDrive for desktop denial of service in redis-server","severity":"medium","exploited":false,"published_at":"2026-05-27T09:16:25.297+00:00","url":"https://junglewise.ai/threats/cve-2024-11399-synology-beedrive-for-desktop-denial-of-service-in-redis-server"},{"cve":"CVE-2025-8074","cvss":5.6,"epss":0.0009,"slug":"cve-2025-8074-origin-validation-error-vulnerability-in-beedrive-in-synology","title":"Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3-13973 allows local users to write arbitrary","severity":"medium","exploited":false,"published_at":"2025-12-04T16:16:23.1+00:00","url":"https://junglewise.ai/threats/cve-2025-8074-origin-validation-error-vulnerability-in-beedrive-in-synology"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}