CVE-2026-101056: Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint

Published Sep 27, 2026
·
Updated

Cloudreve before 4.16.1 fails to revalidate share access when restoring cached navigator state from a contexthint UUID. Attackers who previously had valid share access can replay the cached hint to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or reaches zero remaining downloads.

Affected Software

1 affected component
Cloudreve Cloudreve<4.16.1

Event History

Sep 27, 2026
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker must previously have had valid access to a share and possess a cached context_hint UUID from that access. No authentication or user interaction is required to replay the hint.

2

What is the exposure window after a share is revoked or becomes unavailable?

A cached context_hint can be replayed to generate signed file URLs for up to 300 seconds after the share is deleted, expires, or has zero remaining downloads.

3

Are deployments affected by default?

The provided information identifies Cloudreve versions before 4.16.1 as affected. It does not state whether any particular default share configuration is required.

4

How can I determine whether a share may still be exposed after revocation?

Treat shares previously accessed by untrusted users as potentially accessible through replayed cached navigator state for up to 300 seconds after deletion, expiry, or download-limit exhaustion. The provided information does not describe a log indicator or detection method.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203