Origin Validation Error in Synology ActiveProtect Agent
CVE-2025-13593

6.1MEDIUM

Key Information:

Vendor

Synology

Vendor
CVE Published:
27 May 2026

What is CVE-2025-13593?

The ActiveProtect Agent by Synology suffers from an origin validation error vulnerability, which allows local users to manipulate file permissions inappropriately. This flaw can enable unauthorized users to write arbitrary files containing restricted content during the installation process. Implementing necessary updates is critical to safeguard systems from potential exploits.

Affected Version(s)

ActiveProtect Agent *

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sheikh Rishad (https://x.com/sheikhrishad0)
.