VYPR
Unrated severityNVD Advisory· Published Feb 24, 2026· Updated Feb 24, 2026

CVE-2026-3091

CVE-2026-3091

Description

An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files during installation by placing a malicious DLL in advance in the same directory as the installer.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.