Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 02 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Information Disclosure via GET Requests with Sensitive Query Strings in Synology Storage Manager |
Tue, 02 Jun 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local attackers to obtain sensitive information. | A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information. |
Mon, 01 Jun 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology diskstation Manager
|
|
| CPEs | cpe:2.3:a:synology:storage_manager:*:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:7.2.1:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:7.2.2:*:*:*:*:*:*:* cpe:2.3:o:synology:diskstation_manager:7.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Synology diskstation Manager
|
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Synology
Synology storage Manager |
|
| Vendors & Products |
Synology
Synology storage Manager |
Wed, 27 May 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 27 May 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Local Information Disclosure via GET Requests with Sensitive Query Strings in Synology Storage Manager |
Wed, 27 May 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local attackers to obtain sensitive information. | |
| Weaknesses | CWE-598 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: synology
Published:
Updated: 2026-06-02T08:28:36.196Z
Reserved: 2026-02-09T06:21:48.344Z
Link: CVE-2026-2237
Updated: 2026-05-27T12:12:16.995Z
Status : Modified
Published: 2026-05-27T09:16:27.877
Modified: 2026-06-17T10:30:36.420
Link: CVE-2026-2237
No data.
OpenCVE Enrichment
Updated: 2026-06-02T12:30:08Z