CVE-2017-16773: Synology Universal Search

High severity, CVSS 8.8. EPSS: 1.4% chance of exploitation in the next 30 days.

Improper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users to bypass permission checks for directories in POSIX mode.

Affected products

  • Synology Universal Search: before 1.0.5-0135 (fixed in 1.0.5-0135)

Published 2018-07-05. Last modified 2026-06-17.