CVE-2026-102155: Security Advisory 0190
An XML External Entity (XXE) injection vulnerability in the WiFi-server Spectralight application allows any authenticated user to send malicious requests, leading to arbitrary local file disclosure and partial denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WiFi-server Spectralight applicationto a version that resolves this vulnerability.Fixed in 2026.2.1Patch Security Advisory 0190