CVE-2026-40535 | Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Desktop API path traversal (EUVD-2026-82795)
A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. It has been declared as critical. Impacted is an unknown function of the component Desktop API. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2026-40535. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More