Cross-site Scripting Vulnerability in Synology Chat Server by Synology
CVE-2026-40541
9CRITICAL
What is CVE-2026-40541?
A vulnerability exists in Synology Chat Server prior to version 2.4.5-22148 due to improper input handling during web page generation. This flaw permits remote authenticated users to exploit the system through UI interactions, potentially allowing them to read or write arbitrary files. Additionally, this vulnerability may facilitate denial-of-service attacks, negatively impacting the availability and functionality of the chat service.
Affected Version(s)
Synology Chat Server *
References
CVSS V3.1
Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Lam Jun Rong and Javier Koh, Cyber Specialists of the Digital and Intelligence Service (DIS) working with the Centre for Strategic Infocomm Technologies (CSIT) and Dr Joseph Teo, CSIT