← Terug naar overzicht

CVE-2026-40541 is a Cross-Site Scripting (XSS) vulnerability found in the extract domain functionality of Synology Chat Server versions prior to 2.4.5-22148. The flaw is classified as an improper neutralization of input during web page generation. Remote authenticated users can exploit this vulnerability through UI interaction to read or write arbitrary files on the system. The vulnerability also enables attackers to conduct denial-of-service (DoS) attacks within Synology DiskStation Manager (DSM). The issue has been addressed in Synology Chat Server version 2.4.5-22148 and later. Synology has published a security advisory (Synology_SA_26_10) detailing the vulnerability and its remediation. The current risk level is rated High.

Affected products

  • Synology Chat Server
  • Synology DiskStation Manager (DSM)

Related CVE's

  • CVE-2026-40541

Categories

  • Email & Messaging
  • Enterprise Applications
  • Web Technologies