PT-2026-99568 · Cloudreve · Cloudreve

·

CVE-2026-101056

·

Published

2026-08-24

·

Updated

2026-09-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Cloudreve versions prior to 4.16.1
Description The software fails to revalidate share access when restoring cached navigator state from a context hint UUID. This allows attackers who previously held valid share access to replay the cached hint to generate signed file URLs for up to 300 seconds after the share has been deleted, expired, or reached the limit of remaining downloads.
Recommendations Update to version 4.16.1 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101056
GHSA-VX2M-JPXR-XV7W
GO-2026-6287

Affected Products

Cloudreve