CVE-2026-100902
Received Received - Intake

Barco ClickShare CX-20 Denial of Service via Wallpaper Upload

Vulnerability report for CVE-2026-100902, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes denial of service. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
barco clickshare_cx-20_gen2 to 02.26.00.0007 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-100902 is a denial of service vulnerability in Barco ClickShare CX-20 Gen2 devices up to firmware version 02.26.00.0007. It involves improper input validation in the wallpaper upload feature. An attacker can exploit this by uploading a maliciously crafted JPEG file with extra data to the /wallpaper endpoint. The device fails to validate the entire file, causing an unhandled server error that corrupts storage.

Detection Guidance

Check if Barco ClickShare CX-20 Gen2 devices are running firmware version 02.26.00.0007. Attempt to upload a polyglot JPEG file with trailing data to the /wallpaper endpoint and observe if an HTTP 500 error occurs or if the HTTPS service becomes unreachable.

Impact Analysis

This vulnerability allows an authenticated attacker to crash the device's web service, making it unresponsive. The device may return persistent HTTP 500 errors or become completely unreachable on port 443. The issue persists after reboots and requires a factory reset to fix. This disrupts normal device operations and may require downtime to restore functionality.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by causing persistent denial of service in Barco ClickShare CX-20 Gen2 devices. Unavailability of the device may disrupt access to critical functions, potentially violating data availability requirements under these regulations. The persistent corruption of storage could also lead to data integrity issues.

Mitigation Strategies

Isolate affected devices from the network to prevent exploitation. Update firmware to a patched version if available. If no patch exists, restrict access to the /wallpaper endpoint via network firewall rules or disable the wallpaper upload feature entirely.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100902. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart