CVE-2026-101056
Deferred Deferred - Pending Action

Cloudreve Share Access Bypass via Cached Context Hint

Vulnerability report for CVE-2026-101056, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulnCheck

Description

Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cloudreve cloudreve to 4.16.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Cloudreve before version 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads.

Detection Guidance

Check Cloudreve logs for repeated use of the same context_hint UUID after share deletion or expiry. Monitor file/url and file/thumb routes for unauthorized signed URL generation requests. Verify if navigator state caching includes share access tokens that bypass validation.

Impact Analysis

This vulnerability allows former recipients of shared files to continue generating signed download URLs even after the share is revoked, expired, or reaches download limits. This bypasses owner controls like share deletion, expiry, download limits, and password checks for up to 300 seconds.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by allowing unauthorized access to shared files even after revocation. GDPR requires data protection and user rights, while HIPAA mandates strict access controls for sensitive health data. The flaw enables former share recipients to generate signed URLs for up to 300 seconds after share deletion or expiry, potentially violating these regulations by permitting continued access to restricted data.

Mitigation Strategies

Upgrade Cloudreve to version 4.16.1 or later. Disable context_hint caching for share access validation. Implement server-side checks to revalidate share permissions before generating signed URLs. Review and revoke any potentially compromised shares.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101056. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart