CVE-2026-101056: Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint
Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a contexthint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker must previously have had valid access to a share and possess a cached context_hint UUID from that access. No authentication or user interaction is required to replay the hint.
What is the exposure window after a share is revoked or becomes unavailable?
A cached context_hint can be replayed to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or has zero remaining downloads.
Are deployments affected by default?
The provided information identifies Cloudreve versions before 4.16.1 as affected. It does not state whether any particular default share configuration is required.
How can I determine whether a share may still be exposed after revocation?
Treat shares previously accessed by untrusted users as potentially accessible through replayed cached navigator state for up to 300 seconds after deletion, expiry, or download-limit exhaustion. The provided information does not describe a log indicator or detection method.