CVE-2026-101048

CVE-2026-101048 published: Cloudreve before 4.17.0 registers the administrative node test endpoints (POST /api/v4/admin/node/test and POST /api/v4/admin/node/test/downloader) without requiring the Admin.Write OAuth scope, unlike the node create/update/delete routes. An OAuth client t...

View full NVD advisory → ← Back to CVE watch