CVE-2026-102157: Security Advisory 0190
An insecure direct object reference (IDOR) vulnerability in a CloudVision CUE file-serving interface may allow an authenticated network user, under specific attack conditions, to access another user's transient data.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CloudVisionto a version that resolves this vulnerability.Fixed in 2026.2.1Patch Security Advisory 0190
Event History
Frequently Asked Questions
Who is exposed to this issue?
Authenticated network users of the CloudVision CUE file-serving interface may be exposed. The issue involves access to another user's transient data under specific attack conditions.
What level of access does an attacker need?
An attacker needs an authenticated network user account and network access to the affected interface. No user interaction is required.
What could an attacker access?
The vulnerability may allow access to another user's transient data. The provided information indicates high confidentiality impact, with no integrity impact and low availability impact.