Incorrect Default Permissions in Synology Assistant Affects Local Users
CVE-2026-4793

7.3HIGH

Key Information:

Vendor

Synology

Vendor
CVE Published:
3 August 2026

What is CVE-2026-4793?

The Synology Assistant application prior to version 7.0.7-50095 has a vulnerability where incorrect default permissions allow local users to read or write arbitrary files. This misconfiguration poses a risk of unauthorized data manipulation and potential denial-of-service attacks during the installation process. Users must upgrade to the latest version to mitigate these security risks.

Affected Version(s)

Synology Assistant *

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
.