CVE-2026-101155: Security Advisory 0189
An authenticated remote attacker with specific permissions can read or write files on the platform filesystem beyond the intended scope through specially crafted requests and/or crafted file uploads to the Software Management Studio Software Repository.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2025.3.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.2.1
Event History
Frequently Asked Questions
Which environments are exposed?
Software Management Studio deployments are exposed where the Software Repository is reachable by an authenticated remote user who has the specific required permissions.
What access does an attacker need?
An attacker must be authenticated remotely and possess specific permissions. Exploitation involves specially crafted requests and/or crafted file uploads to the Software Repository.