CVE-2018-8926: Synology Photo Station

High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.

Permissive regular expression vulnerability in synophoto_dsm_user in Synology Photo Station before 6.8.5-3471 and before 6.3-2975 allows remote authenticated users to conduct privilege escalation attacks via the fullname parameter.

Affected products

  • Synology Photo Station: from 6.3-2958, up to and including 6.3-2975; from 6.8.0-3456, before 6.8.5-3471 (fixed in 6.8.5-3471)

Published 2018-06-08. Last modified 2026-06-17.