CVE-2026-101269: Incorrect session validation for API-uploaded files
Published Sep 29, 2026
·Updated
The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless.
Event History
Sep 29, 2026
CVE Published
via MITRE·12:01 PM
Data Sourced
via MITRE·12:01 PM
Description
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which API users share the same session token?
All token-based API users use the same session token under the affected mechanism.
2
What limits the practical exposure of uploaded files?
API-uploaded files are referenced by randomly generated UUIDs and exist for only one day, which the advisory describes as making the practical risk virtually nonexistent.
3
Is the additional file-to-authentication binding protection still effective?
No. The advisory states that the issue renders that added protection mechanism useless.