CVE-2026-102140
Received Received - Intake

Authenticated Administrative Import File Validation Bypass in

Vulnerability report for CVE-2026-102140, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description

An authenticated administrator could initiate an administrative import using a file whose contents were not fully verified, because the import validated only the file's header rather than the complete file. This could allow unverified or forged content to be accepted and processed, affecting the integrity of the imported data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an authenticated administrator to import a file that hasn't been fully verified. Instead of checking the entire file, only the header is validated, which could let unverified or forged content be processed. This affects the integrity of the imported data.

Impact Analysis

An attacker with admin access could upload malicious or incorrect data, leading to system corruption, data breaches, or operational disruptions. The integrity of critical data could be compromised.

Compliance Impact

This vulnerability could violate compliance requirements that mandate data integrity and security, such as GDPR's accuracy principle or HIPAA's integrity safeguards. Unverified data imports may lead to non-compliance penalties.

Mitigation Strategies

Immediately restrict administrative import privileges to trusted users only. Ensure all import files are fully verified before processing, including content validation beyond just the file header. Monitor import logs for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102140. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart