CVE-2026-22899: File Station 5
A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack.
We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5208 and later
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
File Station 5to a version that resolves this vulnerability.Fixed in 5.5.6.5208
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22899?
CVE-2026-22899 has a medium severity rating with a CVSS score of 5.3.
What is CVE-2026-22899?
CVE-2026-22899 is a NULL pointer dereference vulnerability affecting File Station 6 which can be exploited for a denial-of-service attack.
How can I fix CVE-2026-22899?
To fix CVE-2026-22899, upgrade to File Station 5 version 5.5.6.5208 or later.
Who is affected by CVE-2026-22899?
CVE-2026-22899 affects users of Synology File Station 6 who have a user account that could be exploited by remote attackers.
What is the impact of CVE-2026-22899?
The impact of CVE-2026-22899 is the potential for a denial-of-service attack if exploited by an attacker with a valid user account.