CVE-2026-4036 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Sharing API sql injection
A vulnerability described as critical has been identified in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. Affected by this vulnerability is an unknown functionality of the component Sharing API. Executing a manipulation can lead to sql injection.
This vulnerability is registered as CVE-2026-4036. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.VulDB Recent EntriesRead More