Server-Side Request Forgery Vulnerability in Cloudreve by Cloudreve
CVE-2026-101048

5.3MEDIUM

Key Information:

Vendor

Cloudreve

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-101048?

An identified vulnerability in Cloudreve versions prior to 4.17.0 allows unauthorized submissions of node definitions through the administrative test endpoints without proper OAuth scope verification. This weakness permits attackers, with only the Admin.Read scope, to craft malicious requests that can lead to server-side request forgery. As a result, this may enable attackers to probe internal services, execute outbound requests to arbitrary URLs, and exploit the Cloudreve environment for unauthorized actions and data leakage.

Affected Version(s)

cloudreve 0 < 4.17.0

cloudreve 4.17.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DavidCarliez
.