๐Ÿ” CVE Alert

CVE-2026-13666

LOW 3.5
CVSS Score
3.5
EPSS Score
0.0%
EPSS Percentile
0th

An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability in Sharing API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write limited files when a victim clicks a sharing URL.

CWE CWE-93
Vendor synology
Product diskstation manager (dsm)
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for synology diskstation manager (dsm)

Be the first to know when new low vulnerabilities affecting synology diskstation manager (dsm) are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

Synology / DiskStation Manager (DSM)
7.4 < 7.4-90075 7.3.2 < 7.3.2-86009-4 7.2.2 < 7.2.2-72806-9 7.2.1 < 7.2.1-69057-12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
synology.com: https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

Credits

Brendan O'Rourke