CVE-2025-13593

Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

medium 6.1 CVSS 3.1
Published: May 27, 2026
Modified: Jun 2, 2026
Vendor: Synology
Product: Activeprotect Agent

Description

Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.

References

Related CVEs