Loading market data...
← Back to CVE feed

CVE-2026-101269

UNKNOWN View on NVD ↗

Description

The mechanism binding API-uploaded files to the uploader's authentication method is not working correctly and the same session token is used for all token-based API users. Since API-uploaded files are refered to by randomly generated UUIDs and only exist for a day, there is virtually no risk, but it renders the added protection mechanism useless.

Published: Sep 29, 2026 13:17 UTC Modified: Sep 29, 2026 21:28 UTC