CVE-2026-2237: Medium severity Synology Storage Manager vulnerability
Published May 27, 2026
·Updated
A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information.
Affected Software
5 affected components
Synology Storage Manager<1.0.1-1100
All of the following
Synology Storage Manager<1.0.1-1100
Any of the following
Synology Diskstation Manager=7.2.1
Synology Diskstation Manager=7.2.2
Synology Diskstation Manager=7.3
Event History
May 27, 2026
CVE Published
via MITRE·08:44 AM
Data Sourced
via MITRE·08:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-2237?
The severity of CVE-2026-2237 is medium with a CVSS score of 6.2.
2
How do I fix CVE-2026-2237?
To fix CVE-2026-2237, upgrade the Synology Storage Manager package to version 1.0.1-1100 or later.
3
Who is affected by CVE-2026-2237?
Local attackers using vulnerable versions of the Synology Storage Manager package can exploit CVE-2026-2237.
4
What type of information can be exposed due to CVE-2026-2237?
CVE-2026-2237 can expose sensitive information through improperly handled GET request query strings.
5
When was CVE-2026-2237 published?
CVE-2026-2237 was published on May 27, 2026.