SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-9491

MEDIUM · CVSS 4.3 EPSS 0.40%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A server-side request forgery (SSRF) vulnerability in the webhook functionality of Synology Chat Server versions prior to 2.4.5-22148 enables remote authenticated users to access non-sensitive information. While the impact is classified as medium, organizations using affected versions should prioritize patching to mitigate potential information leakage risks. This is particularly relevant for system administrators and security teams managing Synology Chat Server deployments.

CVE
CVE-2026-9491
Severity
MEDIUM
CVSS
4.3
EPSS
0.40%

Original NVD Description

A server-ide request forgery (SSRF) vulnerability in webhook in Synology Chat Server before 2.4.5-22148 allows remote authenticated users to obtain non-sensitive information.