CVE-2026-13683: SQL Injection
Published Sep 18, 2026
·Updated
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in EventScheduler API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users with administrator privileges to obtain non-sensitive information.
Affected Software
1 affected component
Synology DiskStation Manager (DSM) EventScheduler API<7.2.1-69057-12, <7.2.2-72806-9, <7.3.2-86009-4, <7.4-90075
Event History
Sep 18, 2026
CVE Published
via MITRE·08:22 AM
Data Sourced
via MITRE·08:22 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which users can exploit this issue?
Exploitation requires remote authentication to DSM with administrator privileges. The disclosed impact is limited to obtaining non-sensitive information.
2
Which DSM releases need to be updated?
Affected versions are DSM releases before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075. Update to the applicable listed build or later.