Junglewise Threat Intelligence

CVE-2026-101056: Cloudreve access control bypass in share validation

CVE-2026-101056 · Severity: medium · CVSS 5.3 · Published 2026-09-27

Technologies: Cloudreve. Vendors: Cloudreve.

Executive brief

Cloudreve is a self-hosted cloud storage platform. When a user shares files with others, the system caches access information using a UUID hint. If an attacker previously had valid access to a share, they can replay this cached hint to download files for up to 5 minutes after the share owner deletes it, blocks it from expiring, or runs out of allowed downloads. This allows unauthorized file access even after the share is supposed to be revoked.

Technical details

The vulnerability is a broken access control issue where the file/url and file/thumb routes accept a client-supplied context_hint UUID that restores cached navigator state without re-validating share access. The shareNavigator.RestoreState function restores the cached shareRoot, which causes the To() function to skip the Root() revalidation that checks share expiry, download limits, and password; an attacker who previously warmed the cache with a valid hint can replay it within the 300-second context-hint TTL to mint signed file URLs after revocation. The attack requires prior knowledge of the shared file paths and prior valid access to the share.

Affected products

  • Cloudreve Cloudreve before 4.16.1

Timeline

  • 2026-09-27: disclosed: Published on NVD and GitHub Security Advisory (GHSA-vx2m-jpxr-xv7w)

References

Related threats