Path Traversal Vulnerability in Synology DiskStation Manager
CVE-2026-40535
6.5MEDIUM
What is CVE-2026-40535?
A path traversal vulnerability exists in the Desktop API of Synology DiskStation Manager, allowing unauthorized remote access to write files in restricted directories. This flaw can be exploited by remote attackers to perform specific limitations on file access and potentially launch limited denial-of-service attacks, impacting system availability and integrity.
Affected Version(s)
DiskStation Manager (DSM) 7.3
DiskStation Manager (DSM) 7.3 < 7.3.2-86009-2
DiskStation Manager (DSM) 7.2.2 < 7.2.2-72806-7