Missing Authentication for Critical Function in Kavita - CVE-2026-44775

 

Missing Authentication for Critical Function in Kavita - CVE-2026-44775

Published: May 5, 2026


Vulnerability identifier: #VU130156
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44775
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive image data.

The vulnerability exists due to missing authentication for critical function in the /api/Reader/image endpoint when handling image requests. A remote attacker can send a specially crafted request with chapterId and page values to disclose sensitive image data.

The apiKey parameter is accepted but not validated, and sequential chapter identifiers allow trivial enumeration of page images across libraries.


Affected software

Kavita

How to mitigate CVE-2026-44775

Install security update from vendor's website.

Kavita - update to 0.9.0

External References

Related Security Bulletins