Vulnerability record · CVE-2022-36534 · published 16 September 2022
CVE-2022-36534: Syncovery 9 for Linux web GUI authenticated RCE via job parameters
Syncovery · Syncovery
Syncovery 9 for Linux v9.47x and below contains multiple remote code execution flaws reached through the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php. An authenticated user can inject commands that execute on the host, making this a serious post-authentication compromise path. The record does not specify the exact injection mechanism or affected build list beyond v9.47x and below.
Description
Super Flexible Software GmbH & Co. KG Syncovery 9 for Linux v9.47x and below was discovered to contain multiple remote code execution (RCE) vulnerabilities via the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityAuthenticated RCE with public exploit references and very high EPSS, though it requires valid credentials and is not in KEV.
What it is
Syncovery 9 for Linux v9.47x and below contains multiple remote code execution flaws reached through the Job_ExecuteBefore and Job_ExecuteAfter parameters at post_profilesettings.php. An authenticated user can inject commands that execute on the host, making this a serious post-authentication compromise path. The record does not specify the exact injection mechanism or affected build list beyond v9.47x and below.
Impact
An attacker with a valid account gains arbitrary command execution on the Syncovery host, allowing full compromise of the server and any data or credentials it can reach.
Attack surface
Reached over the network through the Syncovery web GUI at post_profilesettings.php; the CVSS vector shows PR:L and UI:N, so a low-privileged authenticated account is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV, but public exploit write-ups exist (Packet Storm and mgm-sp references tagged Exploit) and EPSS is 0.52 at the 98.9th percentile, indicating elevated near-term exploitation likelihood.
What to do
- Upgrade Syncovery 9 for Linux beyond v9.47x to a fixed release from the vendor.
- Restrict network access to the Syncovery web GUI to trusted management networks.
- Audit and minimize accounts with access to profile settings; remove unused or shared logins.
- Review job configurations for unexpected Job_ExecuteBefore and Job_ExecuteAfter values.
- Monitor and alert on command execution spawned by the Syncovery service account.
Detection
- Alert on POST requests to post_profilesettings.php containing shell metacharacters or command strings in Job_ExecuteBefore or Job_ExecuteAfter.
- Monitor child processes spawned by the Syncovery service account for shells or unexpected binaries.
- Review web server and Syncovery logs for profile settings changes followed by process creation on the host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/170245/Syncovery-For-Linux-Web-GUI-Authenticated-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.mgm-sp.com/en/multiple-vulnerabilities-in-syncovery-for-linux/ | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/170245/Syncovery-For-Linux-Web-GUI-Authenticated-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.mgm-sp.com/en/multiple-vulnerabilities-in-syncovery-for-linux/ | ExploitThird Party Advisory |
Track CVE-2022-36534 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-36534), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.