Medium severity5.3NVD Advisory· Published Sep 27, 2026· Updated Sep 27, 2026
CVE-2026-101056
CVE-2026-101056
Description
Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.