Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101048— Cloudreve before 4.17.0 SSRF via Admin.Read OAuth scope

Quick assessment

Affected
cloudreve cloudreve
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Cloudreve 4.17.0 之前的版本中,管理员节点测试端点(POST /api/v4/admin/node/test 和 POST /api/v4/admin/node/test/downloader)在注册时未要求 Admin.Write OAuth 权限范围,而节点创建/更新/删除路由则有此要求。因此,一个仅被授予 Admin.Read 范围并经管理员授权的 OAuth 客户端,可以提交攻击者控制的节点定义,从而促使 Cloudreve 服务器向任意 URL 发起出站请求。这导致盲服务端请求伪造(Bli

CVSS 5.4 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101048

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cloudreve before 4.17.0 SSRF via Admin.Read OAuth scope
Source: CVE Program / CVE List V5
Vulnerability Description
Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader) without requiring the Admin.Write OAuth scope, unlike the node create/update/delete routes. An OAuth client that has been authorized by an administrator with only the Admin.Read scope can therefore submit attacker-controlled node definitions and cause the Cloudreve server to issue outbound requests to arbitrary URLs, enabling blind server-side request forgery, internal service probing, and delivery of signed Cloudreve slave-style requests to attacker-chosen endpoints.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
cloudreve cloudreve 0 ~ 4.17.0 -

II. Public POCs for CVE-2026-101048

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101048

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-101048 (1)

Other References for CVE-2026-101048 (1)

Same Patch Batch · cloudreve · 2026-09-27 · 3 CVEs total

CVE-2026-101056 5.3 MEDIUM Cloudreve before 4.16.1 Authentication Bypass via Cached Context Hint
CVE-2026-101051 3.1 LOW Cloudreve before 4.16.1 Path Traversal via Remote Download

IV. Related Vulnerabilities

V. Comments for CVE-2026-101048

No comments yet


Leave a comment