CVE-2026-3091 PUBLISHED

Assigner: synology
Reserved: 24.02.2026 Published: 24.02.2026 Updated: 24.02.2026

An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files during installation by placing a malicious DLL in advance in the same directory as the installer.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS Score: 6.7

Product Status

Vendor Synology
Product Synology Presto Client
Versions Default: affected
  • affected from * to 2.1.3-0672 (excl.)

Credits

  • Sahil Shah finder

References

Problem Types

  • Uncontrolled Search Path Element CWE