CVE-2026-101154: Security Advisory 0189
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Network Provisioning Image Repository.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2025.3.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.2.1
Event History
Frequently Asked Questions
Who is exposed to this issue?
Platforms with access to the Network Provisioning Image Repository are exposed if an authenticated remote user has the specific permissions required to submit crafted requests or file uploads. The attack is remote and does not require user interaction.
What level of access does an attacker need?
The attacker must already be authenticated and hold specific permissions. The provided information does not identify which permissions or roles satisfy that requirement.
What could a successful attacker do?
A successful attacker can read or write files on the platform filesystem outside the intended repository scope. This can affect confidentiality, integrity, and availability.