CVE-2026-101158
HIGH
NVD
CVSS Score
8.4
Severity
HIGH
Published
Oct 06, 2026
Vendor
unknown
Description
A missing input validation vulnerability in the Fileserver upload API allows an authenticated attacker with file upload privileges to execute stored cross-site scripting (XSS). Successful exploitation could enable the attacker to hijack another CloudVision user's web session, potentially granting full access to their account and administrative permissions.