CVE-2026-4793: Synology Assistant

High severity, CVSS 7.3. EPSS: 0.1% chance of exploitation in the next 30 days.

An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.

Affected products

  • Synology Assistant: before 7.0.7-50095 (fixed in 7.0.7-50095)

Published 2026-08-03. Last modified 2026-08-21.