CVE-2026-13673
8.8Synology · DiskStation Manager (DSM)
A vulnerability in the LDAP API of Synology DiskStation Manager allows remote authenticated users to perform unauthorized file operations and denial of service attacks.
Executive summary
A critical permission assignment flaw in Synology DiskStation Manager allows authenticated users to compromise system files or disrupt service availability.
Vulnerability
The flaw is an incorrect permission assignment for critical resources (CWE-732) within the LDAP API, which permits remote authenticated users to read or write arbitrary files and trigger denial of service conditions.
Business impact
Successful exploitation poses a significant threat to data confidentiality and integrity, as attackers can access or modify sensitive files on the storage device. With a CVSS score of 8.8, this high severity vulnerability could lead to total system compromise or prolonged operational downtime. Organizations relying on Synology devices for centralized file storage or directory services face elevated risk of unauthorized data exposure and service disruption.
Remediation
Immediate Action: Update Synology DiskStation Manager (DSM) to the versions specified in the vendor security advisory (7.4-90075, 7.3.2-86009-4, 7.2.2-72806-9, or 7.2.1-69057-12).
Proactive Monitoring: Review system access logs for unusual LDAP API activity or unauthorized file access attempts originating from standard user accounts.
Compensating Controls: Restrict network access to the DSM management interface and LDAP services to trusted internal subnets to minimize the attack surface.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for arbitrary file manipulation, this vulnerability must be treated with high priority. Administrators should audit their current DSM versions immediately and schedule maintenance windows to apply the necessary security updates provided by Synology. Failure to patch these systems leaves the underlying file system and directory services exposed to malicious actors with existing account access.
More Synology CVEs
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Lam Jun Rong (https://jro.sg), per the CVE Program record.