AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-102110.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 5.9CVSS 3.1 · 9119a7d8-5eab-497f-8521-727c672e3725
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSUndergoing AnalysisModified Oct 01, 2026

Disclosure summary

An endpoint used during initial appliance setup did not require authentication and did not correctly enforce its intended state precondition, so during the initial activation window an unauthenticated network attacker could repeatedly re-trigger the privileged activation process. This could disrupt setup and leave the appliance in an incompletely configured state. The issue is only reachable while an appliance is being activated for the first time and not yet fully configured.

Source-reported weakness categories

CWE-306, CWE-670

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

NIST National Vulnerability Database · NVD-CVE-2026-102110

Open original source · Updated Oct 01, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-09-30T17:16:57-04:00
MODIFIED 2026-10-01T10:17:14-04:00
INGESTED 2026-10-06T11:44:59-04:00