CVE-2026-40536
published 2026-09-18CVE-2026-40536: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before…
PriorityP425medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.37%
30.8th percentile
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| synology | diskstation_manager | >= 7.2.1 < 7.2.1-69057-10 | 7.2.1-69057-10 |
| synology | diskstation_manager | >= 7.2.2 < 7.2.2-72806-7 | 7.2.2-72806-7 |
| synology | diskstation_manager | >= 7.3 < 7.3.2-86009-2 | 7.3.2-86009-2 |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Audio API path traversal (EUVD-2026-82790 / WID-SEC-2026-1125)
vuldb·2026-09-20·CVSS 4.3
CVE-2026-40536 [MEDIUM] Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1 Audio API path traversal (EUVD-2026-82790 / WID-SEC-2026-1125)
A vulnerability was found in Synology DiskStation Manager up to 7.2.0/7.2.2-72806-6/7.3.2-86009-1. It has been rated as problematic. The affected element is an unknown function of the component Audio API. The manipulation leads to path traversal.
This vulnerability is referenced as CVE-2026-40536. Remote exploitation of the attack is possible. No exploit is available.
Upgrading the affected component is advised.
GHSA
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-
ghsa_unreviewed·2026-09-18
CVE-2026-40536 [MEDIUM] CWE-22 An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology DiskStation Manager (DSM) before 7.2.1-69057-10, 7.2.2-72806-7 and 7.3.2-86009-2 allows remote authenticated users to obtain non-sensitive information.
CISA
SolarWinds Web Help Desk Security Control Bypass Vulnerability
cisa·2026-02-12·CVSS 9.8
CVE-2025-40536 [HIGH] CWE-693 SolarWinds Web Help Desk Security Control Bypass Vulnerability
Vulnerability: SolarWinds Web Help Desk Security Control Bypass Vulnerability
Affected: SolarWinds Web Help Desk
SolarWinds Web Help Desk contains a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://documentation.solarwinds.com/en/success_center/whd/content/release_notes/whd_2026-1_release_notes.htm ; https://www.solarwinds.com/trust-center/security-advisories/CVE-2025-40536 ; https://nvd.nist.gov/vuln/detail/CVE-2025-40536
Remediation Due Date: 2026-02-15
Suricata
ET WEB_SPECIFIC_APPS SolarWinds Web Help Desk Authentication Bypass (CVE-2025-40536)
suricata·2026-01-29·CVSS 8.1
CVE-2025-40536 [HIGH] ET WEB_SPECIFIC_APPS SolarWinds Web Help Desk Authentication Bypass (CVE-2025-40536)
ET WEB_SPECIFIC_APPS SolarWinds Web Help Desk Authentication Bypass (CVE-2025-40536)
Rule: alert http any any -> $HOME_NET any (msg:"ET WEB_SPECIFIC_APPS SolarWinds Web Help Desk Authentication Bypass (CVE-2025-40536)"; flow:established,to_server; http.uri; content:"/helpdesk/WebObjects/Helpdesk.woa/wo/"; fast_pattern; content:"/ajax/"; content:"wopage|3d|"; http.method; content:"GET"; reference:url,horizon3.ai/attack-research/cve-2025-40551-another-solarwinds-web-help-desk-deserialization-issue/; reference:cve,2025-40536; classtype:web-application-attack; sid:2067188; rev:1; metadata:affected_product SolarWinds, attack_target Server, tls_state TLSDecrypt, created_at 2026_01_29, cve CVE_2025_40536, deployment Perimeter, deployment Internal, deployment SSLDecrypt, confidence Medium, signat
Nuclei
SolarWinds Web Help Desk < 2026.1 - Unauthenticated JNDI Injection RCE
nuclei·CVSS 9.8
CVE-2025-40551 [HIGH] SolarWinds Web Help Desk < 2026.1 - Unauthenticated JNDI Injection RCE
SolarWinds Web Help Desk < 2026.1 - Unauthenticated JNDI Injection RCE
SolarWinds Web Help Desk before version 2026.1 contains an insecure deserialization vulnerability in the jabsorb JSON-RPC library. When chained with a CSRF whitelist bypass (CVE-2025-40536), remote unauthenticated attackers can exploit JNDI injection via the Apache Xalan JNDIConnectionPool class to achieve remote code execution. The bypass involves including "/ajax/" in a query parameter to circumvent URI validation, while switching from "/ajax/" to "/wo/" endpoints bypasses payload sanitization routines.
Template:
id: CVE-2025-40551
info:
name: SolarWinds Web Help Desk < 2026.1 - Unauthenticated JNDI Injection RCE
author: Horizon3.ai
severity: critical
description: |
SolarWinds Web Help Desk before version 2026.1 c
No writeups or analysis indexed.
2026-09-18
Published