CVE-2026-101048 Details
Description
Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader) without requiring the Admin.Write OAuth scope, unlike the node create/update/delete routes. An OAuth client that has been authorized by an administrator with only the Admin.Read scope can therefore submit attacker-controlled node definitions and cause the Cloudreve server to issue outbound requests to arbitrary URLs, enabling blind server-side request forgery, internal service probing, and delivery of signed Cloudreve slave-style requests to attacker-chosen endpoints.
A server-side request forgery (SSRF) vulnerability has been identified in Cloudreve versions prior to 4.17.0. The issue arises because the application registers administrative node test endpoints without requiring the Admin.Write OAuth scope. This oversight allows an OAuth client authorized by an administrator with only the Admin.Read scope to submit attacker-controlled node definitions. As a result, the Cloudreve server can be manipulated to make outbound requests to arbitrary URLs. This vulnerability could be exploited for blind SSRF, internal service probing, and delivering signed Cloudreve slave-style requests to endpoints chosen by the attacker.
To address this vulnerability, add the Admin.Write scope requirement to the affected node test routes. Additionally, consider implementing SSRF validation or network egress controls for all admin-supplied test URLs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cloudreve/cloudreve/security/advisories/GHSA-v6w6-358x-2433 | [email protected] | AdvisoryExploitRemedyVendor |
| https://www.vulncheck.com/advisories/cloudreve-before-4.17.0-ssrf-via-admin-read-oauth-scope | [email protected] | Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cloudreve | <= 4.16.1 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 27, 2026 | New CVE Received | [email protected] |
Volerion