An access-control flaw in the CV-CUE backend may allow an unauthenticated network attacker to access functionality intended only for internal services. Successful exploitation may expose sensitive location information or disrupt affected services.
To be vulnerable, CV-CUE backend (wifimanager) must be enabled and running. To inspect the status of wifimanager:
[root@]# cvpi status wifimanager
Executing command. This may take some time...
Completed 1/1 discovered actions
primary components total:1 running:1 disabled:0
There is no mitigation or workaround available for this issue.
CVE-2026-102159 has been fixed in the following releases:
- 2026.2.1 and later releases