CVE-2026-40541: XSS
Published Aug 28, 2026
·Updated
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-service attacks in DSM.
Affected Software
1 affected component
Synology Chat Server<2.4.5-22148
Event History
Aug 28, 2026
CVE Published
via MITRE·07:07 AM
Data Sourced
via MITRE·07:07 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Synology Chat Server installations running versions before 2.4.5-22148 are affected.
2
What access does an attacker need to exploit this issue?
The attacker must be remotely authenticated and must induce a user-interface interaction. The issue is network-reachable and has low attack complexity.
3
What impact can successful exploitation have?
An attacker may read or write arbitrary files and cause denial of service in DSM. The reported impact includes high confidentiality, integrity, and availability effects.