CVE-2017-15891: Synology Calendar

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

Improper access control vulnerability in SYNO.Cal.EventBase in Synology Calendar before 2.0.1-0242 allows remote authenticated users to modify calendar event via unspecified vectors.

Affected products

  • Synology Calendar: before 2.0.1-0242 (fixed in 2.0.1-0242)

Published 2017-12-08. Last modified 2026-06-17.