Cross-site Scripting Vulnerability in Synology Chat Server by Synology
CVE-2026-40541

9CRITICAL

Key Information:

Vendor

Synology

Vendor
CVE Published:
28 August 2026

What is CVE-2026-40541?

A vulnerability exists in Synology Chat Server prior to version 2.4.5-22148 due to improper input handling during web page generation. This flaw permits remote authenticated users to exploit the system through UI interactions, potentially allowing them to read or write arbitrary files. Additionally, this vulnerability may facilitate denial-of-service attacks, negatively impacting the availability and functionality of the chat service.

Affected Version(s)

Synology Chat Server *

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lam Jun Rong and Javier Koh, Cyber Specialists of the Digital and Intelligence Service (DIS) working with the Centre for Strategic Infocomm Technologies (CSIT) and Dr Joseph Teo, CSIT
.