CVE-2026-102137

An authenticated administrator could bypass the content validation applied to an administrative file upload and store a file containing dangerous content on the appliance. This did not by itself result in code execution, which would require a separate vulnerability to run the stored file.

  • Published Sep 30, 2026
  • CVSS 4.1 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-102137 at the National Vulnerability Database