CVE-2026-9491: SSRF
Published Aug 28, 2026
·Updated
A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information.
Affected Software
1 affected component
Synology Chat Server<2.4.5-22148
Event History
Aug 28, 2026
CVE Published
via MITRE·07:07 AM
Data Sourced
via MITRE·07:07 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A remote attacker must be authenticated to Synology Chat Server. The provided severity vector indicates low attack complexity and no user interaction requirement.
2
What is the impact if exploitation succeeds?
The issue allows server-side request forgery through the webhook feature and may expose non-sensitive information. The supplied vector indicates low confidentiality impact, with no integrity or availability impact.
3
Which versions should be remediated?
Synology Chat Server versions before 2.4.5-22148 are affected. Upgrade to version 2.4.5-22148 or later.