Unrated severityNVD Advisory· Published Feb 24, 2026· Updated Feb 24, 2026
CVE-2026-3091
CVE-2026-3091
Description
An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files during installation by placing a malicious DLL in advance in the same directory as the installer.
Affected products
2- Range: <2.1.3-0672
- Synology/Synology Presto Clientv5Range: *
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.synology.com/en-global/security/advisory/Synology_SA_26_02mitrevendor-advisory
News mentions
0No linked articles in our index yet.