Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads.
Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint
Problem type
Affected products
cloudreve
< 4.16.1 - AFFECTED
4.16.1 - UNAFFECTED
References
https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vx2m-jpxr-xv7w
https://www.vulncheck.com/advisories/cloudreve-before-4.16.1-authentication-bypass-via-cached-context-hint
GitHub Security Advisories
GHSA-qh53-mf6v-496j
Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state...
https://github.com/advisories/GHSA-qh53-mf6v-496jCloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads.
https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vx2m-jpxr-xv7w
https://nvd.nist.gov/vuln/detail/CVE-2026-101056
https://www.vulncheck.com/advisories/cloudreve-before-4.16.1-authentication-bypass-via-cached-context-hint
https://github.com/advisories/GHSA-qh53-mf6v-496j
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-101056Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-101056",
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"dateUpdated": "2026-09-27T17:02:38.060Z",
"dateReserved": "2026-09-27T16:38:56.427Z",
"datePublished": "2026-09-27T17:02:38.060Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck",
"dateUpdated": "2026-09-27T17:02:38.060Z"
},
"datePublic": "2026-06-13T00:00:00.000Z",
"title": "Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint",
"descriptions": [
{
"lang": "en",
"value": "Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads."
}
],
"affected": [
{
"vendor": "cloudreve",
"product": "cloudreve",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThan": "4.16.1"
},
{
"version": "4.16.1",
"status": "unaffected",
"versionType": "semver"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Incorrect Authorization",
"cweId": "CWE-863",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://github.com/cloudreve/cloudreve/security/advisories/GHSA-vx2m-jpxr-xv7w",
"name": "GitHub Security Advisory (GHSA-vx2m-jpxr-xv7w)",
"tags": [
"vendor-advisory"
]
},
{
"url": "https://www.vulncheck.com/advisories/cloudreve-before-4.16.1-authentication-bypass-via-cached-context-hint",
"name": "VulnCheck Advisory: Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint",
"tags": [
"third-party-advisory"
]
}
],
"metrics": [
{
"format": "CVSS"
},
{
"format": "CVSS",
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 5.3,
"baseSeverity": "MEDIUM"
}
}
],
"credits": [
{
"lang": "en",
"value": "riodrwn",
"type": "reporter"
}
]
}
}
}