CVE-2026-40530
published 2026-09-18CVE-2026-40530: An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10…
PriorityP347high8CVSS 3.1
AVNACLPRLUIRSUCHIHAH
EPSS
0.35%
28.4th percentile
An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| synology | diskstation_manager | >= 7.2.1 < 7.2.1-69057-10 | 7.2.1-69057-10 |
| synology | diskstation_manager | >= 7.2.2 < 7.2.2-72806-7 | 7.2.2-72806-7 |
| synology | diskstation_manager | >= 7.3 < 7.3.2-86009-2 | 7.3.2-86009-2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 User API crlf injection (WID-SEC-2026-1125)
vuldb·2026-09-20·CVSS 8.0
CVE-2026-40530 [HIGH] Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 User API crlf injection (WID-SEC-2026-1125)
A vulnerability identified as very critical has been detected in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. This affects an unknown function of the component User API. This manipulation causes crlf injection.
This vulnerability is tracked as CVE-2026-40530. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
GHSA
An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote aut
ghsa_unreviewed·2026-09-18
CVE-2026-40530 [HIGH] CWE-93 An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote aut
An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to read or write arbitrary files and conduct denial-of-service attacks after the system is rebooted.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-18
Published