Description

An uncontrolled search path element vulnerability in Synology Presto Client before 2.1.3-0672 allows local users to read or write arbitrary files during installation by placing a malicious DLL in advance in the same directory as the installer.

INFO

Published Date :

2026-02-24T02:31:20.298Z

Last Modified :

2026-02-24T20:48:54.091Z

Source :

synology
AFFECTED PRODUCTS

The following products are affected by CVE-2026-3091 vulnerability.

Vendors Products
Synology
  • Presto Client
  • Synology Presto Client
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-3091.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact