2026-09-27 17:2CVE-2026-101056VulnCheck
PUBLISHED5.2CWE-863

Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint

Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads.

Problem type

Affected products

cloudreve

cloudreve

< 4.16.1 - AFFECTED

4.16.1 - UNAFFECTED

References

GitHub Security Advisories

GHSA-qh53-mf6v-496j

Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state...

https://github.com/advisories/GHSA-qh53-mf6v-496j

Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-101056
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-101056",
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "dateUpdated": "2026-09-27T17:02:38.060Z",
    "dateReserved": "2026-09-27T16:38:56.427Z",
    "datePublished": "2026-09-27T17:02:38.060Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck",
        "dateUpdated": "2026-09-27T17:02:38.060Z"
      },
      "datePublic": "2026-06-13T00:00:00.000Z",
      "title": "Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint",
      "descriptions": [
        {
          "lang": "en",
          "value": "Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads."
        }
      ],
      "affected": [
        {
          "vendor": "cloudreve",
          "product": "cloudreve",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThan": "4.16.1"
            },
            {
              "version": "4.16.1",
              "status": "unaffected",
              "versionType": "semver"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "Incorrect Authorization",
              "cweId": "CWE-863",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vx2m-jpxr-xv7w",
          "name": "GitHub Security Advisory (GHSA-vx2m-jpxr-xv7w)",
          "tags": [
            "vendor-advisory"
          ]
        },
        {
          "url": "https://www.vulncheck.com/advisories/cloudreve-before-4.16.1-authentication-bypass-via-cached-context-hint",
          "name": "VulnCheck Advisory: Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint",
          "tags": [
            "third-party-advisory"
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS"
        },
        {
          "format": "CVSS",
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "attackVector": "NETWORK",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "NONE",
            "scope": "UNCHANGED",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "riodrwn",
          "type": "reporter"
        }
      ]
    }
  }
}