Authorization bypass through user-controlled key in Kavita - CVE-2026-44776

 

Authorization bypass through user-controlled key in Kavita - CVE-2026-44776

Published: May 5, 2026


Vulnerability identifier: #VU130157
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-44776
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper access control in /api/Download/* endpoints and /api/Chapter endpoint when handling requests with user-supplied chapterId, volumeId, or seriesId values. A remote privileged user can send crafted requests with guessed or enumerated IDs to disclose sensitive information.

Sequential integer entity IDs make content enumeration easier, and the issue affects file downloads, file size queries, and chapter metadata retrieval for libraries the user is not assigned to.


Affected software

Kavita

How to mitigate CVE-2026-44776

Install security update from vendor's website.

Kavita - update to 0.8.9.1

External References

Related Security Bulletins