CVE-2026-2237

A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information.

medium 6.2 CVSS 3.1
Published: May 27, 2026
Modified: Jun 2, 2026
Vendor: Synology
Product: Storage Manager
Versions: 7.2.1,7.2.2,7.3

Description

A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager package before 1.0.1-1100 allows local users on Windows to obtain sensitive information.

References

Related CVEs