---
id: CVE-2026-100902
title: >-
  A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to
  02.26.00.0007
summary: >-
  A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to
  02.26.00.0007. Affected by this issue is some unknown functionality of the
  file /wallpaper of the component Wallpaper Upload. This manipulation of the
  argument wallpaper…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-404
vendor: Barco
product: ClickShare CX-20 Gen2
affected:
  - clickshare_cx-20_gen2 02.26.00.0007
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T04:16:56.207'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100902'
references:
  - url: 'https://github.com/0xWKZER/-security-disclosures/blob/main/Barco001.md'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-100902'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/919384'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/410852'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/410852/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-28T04:02:46.417Z'
---

## Overview

A vulnerability was determined in Barco ClickShare CX-20 Gen2 up to 02.26.00.0007. Affected by this issue is some unknown functionality of the file /wallpaper of the component Wallpaper Upload. This manipulation of the argument wallpaper causes denial of service. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
