CVE-2026-13684

9.8

Synology · DiskStation Manager (DSM)

An improper output encoding vulnerability in the SCGI component of Synology DSM allows unauthenticated remote attackers to perform arbitrary file read, write, and denial of service operations.

Executive summary

A critical vulnerability in Synology DiskStation Manager allows unauthenticated remote attackers to compromise system files and disrupt services, necessitating immediate patching.

Vulnerability

This flaw, identified as CWE-116, stems from improper encoding or escaping of output within the SCGI interface. The vulnerability is exploitable by unauthenticated remote attackers, enabling them to gain unauthorized file system access or trigger a denial of service.

Business impact

The ability for an attacker to read or write arbitrary files on a storage device is a critical security failure, potentially leading to total system compromise, exfiltration of sensitive data, or the injection of malicious payloads. Given the CVSS score of 9.8, this vulnerability presents an extreme risk to business continuity and data integrity. Organizations should treat this as a high priority incident to prevent unauthorized access to corporate storage assets.

Remediation

Immediate Action: Update Synology DiskStation Manager to the fixed versions: 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, or 7.4-90075 immediately.

Proactive Monitoring: Audit system access logs for anomalous SCGI requests or unexpected file modification events that correlate with the timing of the vulnerability disclosure.

Compensating Controls: Deploy a Web Application Firewall or restrict network access to the DSM management interface to trusted IP addresses only, limiting the exposure of the vulnerable service to the public internet.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the severity of this vulnerability and the potential for complete system compromise, administrators must prioritize the application of the provided patches. Failure to update affected Synology devices exposes the entire storage environment to remote exploitation. Perform the update during the next available maintenance window, or immediately if the device is exposed to the public internet.

More Synology CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by Lam Jun Rong (https://jro.sg), per the CVE Program record.