CVE-2024-50630: Synology Drive Server
High severity, CVSS 7.5. EPSS: 24.6% chance of exploitation in the next 30 days.
Missing authentication for critical function vulnerability in the webapi component in Synology Drive Server before 3.0.4-12699, 3.2.1-23280, 3.5.0-26085 and 3.5.1-26102 allows remote attackers to obtain administrator credentials via unspecified vectors.
Affected products
- Synology Drive Server: before 3.0.4-12699 (fixed in 3.0.4-12699); before 3.2.1-23280 (fixed in 3.2.1-23280); before 3.5.0-26085 (fixed in 3.5.0-26085); before 3.5.1-26102 (fixed in 3.5.1-26102)
Published 2025-03-19. Last modified 2026-06-17.