CVE-2026-102137
Received Received - Intake

Authenticated File Upload Bypass in Appliance

Vulnerability report for CVE-2026-102137, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

An authenticated administrator could bypass the content validation applied to an administrative file upload and store a file containing dangerous content on the appliance. This did not by itself result in code execution, which would require a separate vulnerability to run the stored file.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a file upload vulnerability where an authenticated administrator can bypass content validation and upload a file with dangerous content to the appliance. The vulnerability does not directly allow code execution but enables storing malicious files that could be exploited later if another vulnerability exists to run the file.

Detection Guidance

This vulnerability requires authenticated administrator access and involves bypassing content validation for file uploads. Detection would involve checking for suspicious file uploads by administrators, particularly files that bypass validation rules. Review server logs for unusual file types or content in administrative upload directories. Inspect file metadata and content for anomalies compared to expected formats.

Impact Analysis

An attacker with administrator access could upload malicious files to the system, potentially leading to data breaches, unauthorized access, or further compromise if combined with another vulnerability. The impact includes confidentiality, integrity, and availability risks as the stored file could be malicious.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by allowing unauthorized access to sensitive data or enabling data breaches. Organizations may fail to protect personal or health information adequately, resulting in legal penalties or reputational damage.

Mitigation Strategies

Restrict administrative file uploads to trusted sources only and validate all uploaded content. Review file storage locations for suspicious files and remove any unauthorized files. Ensure separate vulnerabilities that could lead to code execution are patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102137. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart