Published:2026/08/17  Last Updated:2026/08/17

JVN#91713656
Improper file access permission settings in Synology Assistant

Overview

Synology Assistant provided by Synology Inc. is configured with an improper file access permission settings.

Products Affected

  • Synology Assistant versions prior to 7.0.7

Description

Synology Assistant provided by Synology Inc. contains the following vulnerability.

  • Incorrect default permissions (CWE-276)
    • CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 5.4
    • CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Base Score 6.7
    • CVE-2026-4793

Impact

Arbitrary code may be executed with SYSTEM privileges by a user who can access the device that the affected product is installed.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Link
Synology Inc. Synology-SA-26:12 Synology Assistant

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2026-000113