CVE-2026-102249 Details
Description
A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /commons/file-editor-save. The manipulation of the argument url/fileKey results in missing authorization. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability allowing unauthenticated server-side request forgery (SSRF) and arbitrary file write has been identified in REBUILD versions through 4.4.11. The issue arises in the '/commons/file-editor-save' endpoint, where missing authorization allows the manipulation of the 'url' and 'fileKey' parameters. This vulnerability can be exploited remotely, with the published exploit potentially being used for attacks.
To address this vulnerability, require authentication and specific authorization for the '/commons/file-editor-save' endpoint. Implement strict validation for the 'url' parameter to prevent SSRF, and ensure that 'fileKey' values are verified before allowing file writes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ASantsSec/CVE/issues/26 | [email protected] | ExploitIssue TrackingRemedy |
| https://vuldb.com/cve/CVE-2026-102249 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/933733 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/411151 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/411151/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| REBUILD | 4.4.7-release (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion