An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
References
| Link | Resource |
|---|---|
| https://www.synology.com/en-global/security/advisory/Synology_SA_25_16 | Vendor Advisory |
Configurations
History
02 Jun 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (en) An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. |
01 Jun 2026, 20:03
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.synology.com/en-global/security/advisory/Synology_SA_25_16 - Vendor Advisory | |
| First Time |
Synology
Synology active Backup For Business Agent |
|
| CPE | cpe:2.3:a:synology:active_backup_for_business_agent:*:*:*:*:*:*:*:* |
27 May 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-27 09:16
Updated : 2026-06-02 16:08
NVD link : CVE-2025-66592
Mitre link : CVE-2025-66592
CVE.ORG link : CVE-2025-66592
JSON object : View
Products Affected
synology
- active_backup_for_business_agent
CWE
CWE-346
Origin Validation Error
