SB2026090788 - Multiple vulnerabilities in Kavita
Published: September 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 9 vulnerabilities.
1) Incorrect authorization (CVE-ID: N/A)
CWE-ID: CWE-863 - Incorrect Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose shared annotation content.
The vulnerability exists due to incorrect authorization in the annotation read endpoints when processing requests for shared annotations. A remote user can request annotations for a chapter, annotation, or series outside their authorized library or age restrictions to disclose shared annotation content.
Exploitation requires annotation sharing to be enabled; it is disabled by default.
2) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to alter another user's dashboard or side-navigation widget visibility.
The vulnerability exists due to authorization bypass through a user-controlled key in the dashboard and side-navigation stream update handlers when processing user-supplied stream identifiers. A remote user can submit identifiers for streams owned by another user to alter their visibility.
The bulk side-navigation visibility endpoint can alter all supplied side-navigation streams in a single request.
3) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to delete another user's saved Smart Filter.
The vulnerability exists due to authorization bypass through a user-controlled key in the DeleteFilter action of the DELETE /api/filter endpoint when handling a filter ID supplied in a request. A remote user can submit a request specifying another user's Smart Filter ID to delete the filter and its referenced dashboard and side-navigation shortcuts.
4) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to delete another user's collection.
The vulnerability exists due to authorization bypass through a user-controlled key in the POST /api/collection/update-series endpoint when processing a request containing another user's collection tag ID. A remote user can remove all series from another user's collection to delete another user's collection.
The collection is deleted only when removing the series empties it.
5) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to modify global CSS themes.
The vulnerability exists due to missing authorization in the theme upload, deletion, and upstream download actions of ThemeController when handling theme management requests. A remote user can upload arbitrary CSS content or delete themes uploaded by other users to modify global CSS themes.
Uploaded theme content is globally listed and can be retrieved without authentication.
6) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose the contents of private reading lists.
The vulnerability exists due to missing authorization in the reading-list items endpoint when retrieving items for a user-controlled reading list identifier. A remote user can request sequential reading list identifiers to disclose the contents of another user's private, non-promoted reading list.
Only items whose series are in a library accessible to the user are returned.
7) Missing Authorization (CVE-ID: N/A)
CWE-ID: CWE-862 - Missing Authorization
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose age-restricted item metadata.
The vulnerability exists due to missing authorization in the reading-list item repository query when retrieving items from a reading list. A remote user can request a reading list identifier to disclose metadata for content above the user's configured age rating.
Only metadata for series in a library accessible to the user is exposed; chapter reading and downloads remain subject to separate access controls.
8) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose file sizes of series, volumes, and chapters in restricted libraries.
The vulnerability exists due to authorization bypass through user-controlled key in the `bulk-volume-size`, `bulk-chapter-size`, and `bulk-series-size` endpoints when processing POST requests containing user-supplied entity ID arrays. A remote user can submit arbitrary series, volume, or chapter IDs to disclose file sizes of restricted entities.
The account must have the Download role.
9) Authorization bypass through user-controlled key (CVE-ID: N/A)
CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to disclose other users' bookmarked page images.
The vulnerability exists due to authorization bypass through user-controlled key in the /api/download/bookmarks endpoint when processing user-supplied bookmark and series identifiers. A remote user can submit another user's bookmark identifier paired with a series identifier they can access to disclose other users' bookmarked page images.
Bookmark identifiers are sequential auto-incrementing integers, enabling their enumeration.
Remediation
Install update from vendor's website.
References
- https://github.com/Kareadita/Kavita/security/advisories/GHSA-gjx7-m655-3grw
- https://github.com/Kareadita/Kavita/security/advisories/GHSA-jhw9-5hj3-mvp4
- https://github.com/Kareadita/Kavita/security/advisories/GHSA-fpjf-pxrq-4xv7
- https://github.com/Kareadita/Kavita/security/advisories/GHSA-8qw5-fgxm-ppjj
- https://github.com/Kareadita/Kavita/security/advisories/GHSA-j48q-94cr-7hq5
- https://github.com/Kareadita/Kavita/security/advisories/GHSA-6cpx-c6v4-4g79
- https://github.com/Kareadita/Kavita/security/advisories/GHSA-jxx7-hp6f-5389
- https://github.com/Kareadita/Kavita/security/advisories/GHSA-x67v-89v8-mf3v