SB2026092050 - Multiple vulnerabilities in Synology DSM
Published: September 20, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 vulnerabilities.
1) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-13684)
CWE-ID: CWE-116 - Improper Encoding or Escaping of Output
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read or write arbitrary files or cause a denial of service.
The vulnerability exists due to improper encoding or escaping of output in SCGI when processing output. A remote attacker can exploit the vulnerability to read or write arbitrary files or cause a denial of service.
2) Insufficient Entropy (CVE-ID: CVE-2026-13639)
CWE-ID: CWE-331 - Insufficient Entropy
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read or write arbitrary files or cause a denial of service.
The vulnerability exists due to insufficient entropy in login logic when handling login attempts. A remote attacker can exploit the vulnerability to read or write arbitrary files or cause a denial of service.
3) Improper Encoding or Escaping of Output (CVE-ID: CVE-2026-13635)
CWE-ID: CWE-116 - Improper Encoding or Escaping of Output
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to obtain non-sensitive information.
The vulnerability exists due to improper encoding or escaping of output in Auth API when processing output. A remote attacker can exploit the vulnerability to obtain non-sensitive information.
4) Incorrect permission assignment for critical resource (CVE-ID: CVE-2026-13673)
CWE-ID: CWE-732 - Incorrect Permission Assignment for Critical Resource
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to read or write arbitrary files or cause a denial of service.
The vulnerability exists due to incorrect permission assignment for critical resource in LDAP API when handling LDAP API requests. A remote user can exploit the vulnerability to read or write arbitrary files or cause a denial of service.
5) External Control of File Name or Path (CVE-ID: CVE-2026-6205)
CWE-ID: CWE-73 - External Control of File Name or Path
CVSSv4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to write arbitrary files or cause a denial of service.
The vulnerability exists due to external control of file name or path in Upload API when handling file uploads. A remote user can exploit the vulnerability to write arbitrary files or cause a denial of service.
6) CRLF injection (CVE-ID: CVE-2026-13666)
CWE-ID: CWE-93 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to write limited files.
The vulnerability exists due to improper neutralization of CRLF sequences in Sharing API when handling sharing URLs. A remote user can exploit the vulnerability to write limited files.
A victim must click a sharing URL.
7) Cross-site scripting (CVE-ID: CVE-2026-13623)
CWE-ID: CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVSSv4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
The vulnerability allows a remote user to read or write limited files.
The vulnerability exists due to cross-site scripting in Theme API when processing input during web page generation. A remote privileged user can submit input to Theme API to read or write limited files.
User interaction is required.
8) SQL injection (CVE-ID: CVE-2026-13683)
CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSSv4: 0 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to obtain non-sensitive information.
The vulnerability exists due to SQL injection in EventScheduler API when processing SQL commands. A remote privileged user can exploit the vulnerability to obtain non-sensitive information.
Remediation
Install update from vendor's website.