Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
References
| Link | Resource |
|---|---|
| https://www.synology.com/en-global/security/advisory/Synology_SA_25_15 | Vendor Advisory |
Configurations
History
02 Jun 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. |
01 Jun 2026, 20:05
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Synology
Synology activeprotect Agent |
|
| CPE | cpe:2.3:a:synology:activeprotect_agent:*:*:*:*:*:*:*:* | |
| References | () https://www.synology.com/en-global/security/advisory/Synology_SA_25_15 - Vendor Advisory |
27 May 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-27 09:16
Updated : 2026-06-02 16:08
NVD link : CVE-2025-13593
Mitre link : CVE-2025-13593
CVE.ORG link : CVE-2025-13593
JSON object : View
Products Affected
synology
- activeprotect_agent
CWE
CWE-346
Origin Validation Error
