Synology-SA-26:12 Synology Assistant

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Important
Status
Resolved

Abstract

Synology has released a security update for the Assistant on Windows to address a vulnerability :
      • CVE-2026-4793 allows local users to read or write arbitrary files and conduct denial-of-service.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
Synology Assistant Important Upgrade to 7.0.7-50095 or above.

Mitigation

None

Detail

Acknowledgement

Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.

Reference

Revision

Revision Date Description
1 2026-08-03 Initial public release.