CVE-2026-101269
Received Received - Intake

Authentication Bypass in File Upload API

Vulnerability report for CVE-2026-101269, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: rami.io

Description

The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in how API-uploaded files are linked to the uploader's authentication method. Instead of using unique session tokens for each user, the same token is applied to all token-based API users. This makes the added protection mechanism ineffective.

Detection Guidance

This vulnerability is related to API-uploaded files and session token handling. Detection would require reviewing API logs for improper token binding to files and checking if session tokens are reused across different API users. No specific commands are provided in the context.

Impact Analysis

The impact is minimal because API-uploaded files are temporary (exist for a day) and identified by random UUIDs. However, the vulnerability weakens the intended security measure of binding files to user authentication.

Mitigation Strategies

Since the vulnerability renders the added protection mechanism useless but poses minimal risk due to file expiration, no immediate action is required. However, review API token binding mechanisms and ensure session tokens are unique per user to restore intended security.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101269. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart