Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 27 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads. | |
| Title | Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint | |
| First Time appeared |
Cloudreve
Cloudreve cloudreve |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:cloudreve:cloudreve:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Cloudreve
Cloudreve cloudreve |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-27T17:02:38.060Z
Reserved: 2026-09-27T16:38:56.427Z
Link: CVE-2026-101056
No data.
Status : Deferred
Published: 2026-09-27T18:16:31.667
Modified: 2026-09-27T18:16:31.777
Link: CVE-2026-101056
No data.
OpenCVE Enrichment
Updated: 2026-09-27T18:30:18Z
-
CWE-863
Incorrect Authorization