CVE-2026-6205: High severity Synology DiskStation Manager (DSM) vulnerability
An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
A remote attacker must be authenticated to DSM and able to interact with the Upload API. The provided information does not identify which DSM account roles or permissions are sufficient.
Which DSM releases need to be updated?
DSM versions before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4, and 7.4-90075 are affected. Update to the applicable listed build or a later release.
What can an attacker do after exploitation?
An authenticated remote attacker can write arbitrary files and cause denial of service. The supplied information does not state that confidentiality impact or code execution is possible.