SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-9548

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability allows remote authenticated users of Synology Chat Server versions prior to 2.4.5-22148 to exploit improper input handling during web page generation, leading to potential cross-site scripting (XSS) attacks. This could enable attackers to read or write restricted files and perform limited denial-of-service attacks within the DiskStation Manager (DSM). Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access and service disruption.

CVE
CVE-2026-9548
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write restricted files and conduct limited denial-of-service attacks in DSM.