CVE-2026-6205 is a vulnerability in Synology Diskstation Manager
Published on September 18, 2026
An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-69057-12, 7.2.2-72806-9, 7.3.2-86009-4 and 7.4-90075 allows remote authenticated users to write arbitrary files and conduct denial-of-service attacks.
Vulnerability Analysis
CVE-2026-6205 can be exploited with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity and availability.
Weakness Type
External Control of File Name or Path
The software allows user input to control or influence paths or file names that are used in filesystem operations.
Products Associated with CVE-2026-6205
Want to know whenever a new CVE is published for Synology Diskstation Manager? stack.watch will email you.
Affected Versions
Synology DiskStation Manager (DSM):- Version 7.4 and below 7.4-90075 is affected.
- Version 7.3.2 and below 7.3.2-86009-4 is affected.
- Version 7.2.2 and below 7.2.2-72806-9 is affected.
- Version 7.2.1 and below 7.2.1-69057-12 is affected.
- Before 7.2.1 is unknown.