Uncontrolled Search Path Element Vulnerability in Synology Presto Client
CVE-2026-3091
6.7MEDIUM
What is CVE-2026-3091?
An uncontrolled search path element vulnerability exists in the Synology Presto Client prior to version 2.1.3-0672. This issue permits local users to exploit a flaw during the software installation process, allowing them to read or write arbitrary files. Attackers can leverage this security gap by placing a malicious DLL file in the same directory as the installation program, potentially compromising system integrity.
Affected Version(s)
Synology Presto Client *