Sceawere

Vulnerability Detail

CVE-2026-101056UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Cloudreve Improper Access Revalidation Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
14h ago
Vendor
cloudreve
Product
cloudreve
Attack Type
Incorrect Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a context_hint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-27T18:16:31.667Z",
  "pubdate": "2026-09-27T18:16:31.667Z",
  "executiveSummary": "Cloudreve versions prior to 4.16.1 are susceptible to an access control bypass vulnerability arising from the improper revalidation of cached navigator states. The flaw resides in the handling of context_hint UUIDs, which store temporary authorization context for file navigation.\nThe vulnerability allows an attacker who previously held legitimate access to a shared resource to continue generating signed file URLs even after the share's access conditions have been revoked. Specifically, the system fails to perform a secondary validation against the current state of the share when a context_hint is provided.\nThis impact extends to scenarios where a share has been explicitly deleted, has expired, or has reached its maximum download threshold. For a window of 300 seconds, the cached state persists, permitting unauthorized access to sensitive files that should otherwise be inaccessible.\nThe risk is categorized as an improper authorization flaw, granting unauthorized retrieval of data. Attackers require a previously active session or share link to exploit the temporal cache window. This vulnerability necessitates an immediate update to version 4.16.1 or later to enforce strict server-side authorization checks upon every access request involving cached context hints.",
  "technicalDetails": "The root cause of this vulnerability is a design flaw in the navigation state management system of Cloudreve. When a user interacts with shared files, the application utilizes a context_hint, represented by a UUID, to maintain the state of the navigator. This hint effectively serves as a proxy for the user's current session or authorization context within that share.\nThe vulnerability manifests because the application fails to re-verify the validity of the share permissions when a request is made using a cached context_hint. Instead of validating the request against the current database-backed state of the share—which would account for status changes such as deletion, expiration, or exhausted download limits—the system relies on the cached authorization context associated with the UUID.\nThe attack flow proceeds as follows: First, an attacker establishes legitimate access to a share, triggering the generation of a context_hint UUID. Once the share's lifecycle is terminated by the owner or the system (due to expiry or download limits), the application's backend state is updated to reflect that access is no longer permitted. However, because the system does not purge or re-authenticate the specific context_hint immediately upon these state changes, the hint remains functionally 'active' in the system's memory or cache buffer.\nAn attacker can then replay the context_hint UUID to the file generation endpoint. The application processes the hint, identifies the previously associated share context, and—lacking a revalidation step—proceeds to generate a signed file URL. This enables the attacker to download or access the files for up to 300 seconds beyond the intended termination point of the share. The exploitation does not require advanced techniques; it is a direct replay of a stale, yet accepted, authorization identifier.\nThe vulnerable component is the share navigation state handler. This affects all Cloudreve versions prior to 4.16.1. The failure effectively bypasses the server-side authorization logic, as the generation of the signed URL occurs without checking if the underlying share resource is still active or authorized for the current user context.\nThe post-exploitation impact includes the unauthorized retrieval of private or expired file content. Because the vulnerability exists within the logic of signed URL generation, an attacker can obtain direct access to file blobs, potentially leading to unauthorized data exfiltration within the defined 300-second window."
}
CVE-2026-101056: Cloudreve Improper Access Revalidation Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere