Back to database
Schedule33Medium5.9VulnerabilityCVE-2026-102110No patch link observed

CVE-2026-102110 — An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so du…

Published Sep 30, 2026, 09:16 PM UTCIngested 8d agoSource NVD(cve-db)CVE-2026-102110

Description

An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-trigger the privileged activation process. This could disrupt setup and leave the appliance in an incompletely configured state. The issue is only reachable while an appliance is being activated for the first time and not yet fully configured.

CVSS v3.1 base metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
5.9

Medium severity

Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.

AV

Network

Attack Vector

AC

High

Attack Complexity

PR

None

Privileges Required

UI

None

User Interaction

S

Unchanged

Scope

C

None

Confidentiality

I

High

Integrity

A

None

Availability