Known Vulnerabilities for Assistant by Synology
Listed below are 3 of the newest known vulnerabilities associated with "Assistant" by "Synology".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-78606 json | Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Acces... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-78581 json | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized data modification via Accessing... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-73847 json | Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant execute_t... | Not Provided | 2026-08-14 | 2026-08-14 |
| CVE-2026-72644 json | Uncaught Exception (CWE-248) in Kibana can lead to a denial of service via Input Data Manipulation (CAPEC-153). An authentica... | Not Provided | 2026-09-01 | 2026-09-01 |
| CVE-2026-72581 json | A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to m... | Not Provided | 2026-08-10 | 2026-08-10 |
| CVE-2026-71247 json | Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fet... | Not Provided | 2026-08-05 | 2026-08-10 |
| CVE-2026-69563 json | Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privil... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-69534 json | Improper neutralization of special elements used in a command ('command injection') in Windows Program Compatibility Assistan... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-68876 json | Heap-based buffer overflow in Windows Program Compatibility Assistant Service allows an authorized attacker to elevate privil... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-68874 json | Out-of-bounds read in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information o... | Not Provided | 2026-09-08 | 2026-09-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Synology | Assistant | 6.2-23733 | |||
| Application | Synology | Assistant | 6.1-15163 | |||
| Application | Synology | Assistant | 6.1-15030 | |||
| Application | Synology | Assistant | 6.0-7319 | |||
| Application | Synology | Assistant | 5.2-5566 | |||
| Application | Synology | Assistant | 5.1-5005 | |||
| Application | Synology | Assistant | 5.1-5002 | |||
| Application | Synology | Assistant | 5.0-4448 | |||
| Application | Synology | Assistant | 5.0-4418 | |||
| Application | Synology | Assistant | 4.3-4359 | |||
| Application | Synology | Assistant | 4.3-4206 | |||
| Application | Synology | Assistant | 4.2-3508 | |||
| Application | Synology | Assistant | 4.2-3179 | |||
| Application | Synology | Assistant | 4.1-2647 | |||
| Application | Synology | Assistant | 4.1-2638 | |||
| Application | Synology | Assistant | 4.1-2636 | |||
| Application | Synology | Assistant | 4.0-2216 | |||
| Application | Synology | Assistant | 4.0-2196 | |||
| Application | Synology | Assistant | 3.2-1920 | |||
| Application | Synology | Assistant | 3.1-1593 |