Synology-SA-26:04 Mail Station

Publish Time: UTC+8

Last Updated: UTC+8

Severity
Moderate
Status
Resolved

Abstract

Synology has released a security update for the Mail Station package in DSM to address a vulnerability:
      • CVE-2026-5129 allows remote authenticated users to read or write limited files.

Please refer to the 'Affected Products' table for the corresponding updates.

Affected Products

Product Severity Fixed Release Availability
Mail Station for DSM 7.3 Moderate Upgrade to 30000001.3.19-20332 or above.
Mail Station for DSM 7.2.2 Moderate Upgrade to 30000001.3.19-20332 or above.
Mail Station for DSM 7.2.1 Moderate Upgrade to 30000001.3.19-20332 or above.

Mitigation

None

Detail

Acknowledgement

chris.au

Revision

Revision Date Description
1 2026-03-31 Initial public release.