CVE-2026-101000 — Nbr100v2
CRITICALCVE-2026-101000 is a critical-severity (CVSS 10) Missing Authorization vulnerability in netcore nbr100v2. No vendor fix is recorded yet; mitigation options are listed below.
A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL…
Description
A vulnerability was determined in Netcore NBR100V2 1.3.240614.030928. This affects the function uci.apply of the file /usr/share/rpcd/acl.d/unauthenticated.json of the component ACL Handler. This manipulation of the argument section causes missing authorization. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Products
nbr100v2netcoreDetection & mitigation playbook
Vendor / applianceDetect
Inventory every netcore nbr100v2 deployment and check each version against the affected-products list above.
Remediation status
No patch has shipped for CVE-2026-101000 yet — track the netcore nbr100v2 advisory for a fixed release and apply the workarounds below in the meantime.
Mitigate without a patch
Put an independent control in front of the weakness: restrict the affected endpoint or interface to trusted networks, require an additional authentication factor or proxy-level check, and invalidate existing sessions and credentials in case the flaw has already been used. Alongside that, restrict the management interface to trusted networks and apply the vendor's recommended configuration mitigations.
Frequently Asked Questions
Is CVE-2026-101000 being exploited in your environment?
Detect and block the exploit chain at execution, on systems you cannot patch yet.