Improper Authentication in Kavita - CVE-2026-47202
Published: May 20, 2026
Kavita
Detailed vulnerability description
The vulnerability allows a remote attacker to take over arbitrary user accounts, including administrator accounts.
The vulnerability exists due to improper authentication in JWT token validation when processing token requests for a specified username. A remote attacker can request a JWT for any user with knowledge of the username to take over arbitrary user accounts, including administrator accounts.