Synology-SA-26:02 Synology Presto Client

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Moderate
Status
Resolved

Abstract

Synology has released a security update for the Presto Client on Windows to address a vulnerability :
      • CVE-2026-3091 allows local users to read or write arbitrary files.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
Synology Presto Client Moderate Upgrade to 2.1.3-0672 or above.

Mitigation

None

Detail

Acknowledgement

Sahil Shah

Reference

CVE-2026-3091

Revision

Revision Date Description
1 2026-02-24 Initial public release.
2 2026-02-24 Disclosed vulnerability details.