Published:2026/08/17 Last Updated:2026/08/17
JVN#91713656
Improper file access permission settings in Synology Assistant
Overview
Synology Assistant provided by Synology Inc. is configured with an improper file access permission settings.
Products Affected
- Synology Assistant versions prior to 7.0.7
Description
Synology Assistant provided by Synology Inc. contains the following vulnerability.
- Incorrect default permissions (CWE-276)
- CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 5.4
- CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Base Score 6.7
- CVE-2026-4793
Impact
Arbitrary code may be executed with SYSTEM privileges by a user who can access the device that the affected product is installed.
Solution
Update the Software
Update the software to the latest version according to the information provided by the developer.
Vendor Status
| Vendor | Link |
| Synology Inc. | Synology-SA-26:12 Synology Assistant |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
|
| JVN iPedia |
JVNDB-2026-000113 |