CVE-2026-101158: Security Advisory 0185
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CloudVisionto a version that resolves this vulnerability.Fixed in 2025.3.4Patch CVE-2026-101158 - Upgrade
Upgrade
CloudVisionto a version that resolves this vulnerability.Fixed in 2026.1.3Patch CVE-2026-101158 - Upgrade
Upgrade
CloudVisionto a version that resolves this vulnerability.Fixed in 2026.2.1Patch CVE-2026-101158
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must be authenticated and have file upload privileges in the Fileserver upload API. Exploitation also requires another CloudVision user to interact with the stored XSS payload.
Who is at risk if the vulnerability is exploited?
CloudVision users whose browser sessions can be targeted by the stored XSS payload are at risk. A compromised session could give the attacker access to the affected user's account and potentially their administrative permissions.
What impact could a successful attack have?
An attacker may hijack another user's CloudVision web session. The advisory indicates this could potentially result in full access to that user's account, including administrative permissions.