Sceawere
Vulnerability Detail
CVE-2026-101048UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Cloudreve SSRF via Admin Test
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 14h ago
- Vendor
- cloudreve
- Product
- cloudreve
- Attack Type
- Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader) without requiring the Admin.Write OAuth scope, unlike the node create/update/delete routes. An OAuth client that has been authorized by an administrator with only the Admin.Read scope can therefore submit attacker-controlled node definitions and cause the Cloudreve server to issue outbound requests to arbitrary URLs, enabling blind server-side request forgery, internal service probing, and delivery of signed Cloudreve slave-style requests to attacker-chosen endpoints.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-09-27T18:16:31.313Z",
"pubdate": "2026-09-27T18:16:31.313Z",
"executiveSummary": "Cloudreve versions prior to 4.17.0 contain a Server-Side Request Forgery (SSRF) vulnerability due to improper authorization checks on administrative node test endpoints. The application fails to validate the presence of the required 'Admin.Write' OAuth scope for specific diagnostic routes. Consequently, an attacker holding an OAuth token with only 'Admin.Read' privileges can interact with sensitive administrative functionality.\nThis flaw enables unauthorized parties to force the Cloudreve server to initiate outbound HTTP requests to arbitrary destinations. By manipulating the node definition parameters, an attacker can conduct internal network reconnaissance, interact with private services accessible to the server, and potentially facilitate further exploitation through server-side request injection. The vulnerability poses a significant risk to organizational infrastructure, as it bypasses intended access control logic, allowing non-privileged clients to leverage the server as a proxy for malicious network activities.",
"technicalDetails": "The vulnerability resides in the administrative node management module of Cloudreve, specifically affecting the POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader endpoints. The root cause is a broken access control implementation where these test-oriented routes were exempted from the mandatory 'Admin.Write' OAuth scope requirement enforced on other administrative node operations, such as creation, modification, or deletion.\nThe attack flow begins with an adversary obtaining a legitimate OAuth client token authorized by an administrator with 'Admin.Read' permissions. Despite the lack of write-level authorization, the application erroneously processes the request to the vulnerable test endpoints. An attacker can supply a crafted JSON payload containing an arbitrary URL or internal service address within the node definition parameters.\nUpon receiving the request, the Cloudreve backend utilizes the provided definition to perform a connectivity check. Because the application logic does not sufficiently sanitize or validate the target destination, it initiates an outbound request to the user-supplied endpoint. This functionality serves as a primitive for SSRF, allowing the attacker to probe the internal network for open ports, enumerate internal services, or trigger HTTP requests to services that trust the origin of the Cloudreve server. Furthermore, since the request is initiated from the server, it may include signed internal headers or credentials associated with 'slave-style' communications, potentially allowing the attacker to interact with internal API gateways or administrative components that rely on implicit server trust.\nThe affected versions are all releases prior to 4.17.0. The exploit requires an existing OAuth authorization context, meaning the attacker must have successfully acquired a 'read-only' token. Once established, the interaction occurs over the standard administrative API interface, making the activity appear as a functional diagnostic call within the application logs, thereby complicating detection without rigorous traffic analysis.\nPost-exploitation, the impact ranges from internal network mapping to the delivery of unauthorized requests to backend services. The ability to manipulate the node test parameters allows for a persistent method of interrogating internal infrastructure, facilitating lateral movement or the exploitation of vulnerable services within the isolated network segment where the Cloudreve instance is deployed."
}