Missing Authorization in Calibre - #VU140779
Published: August 3, 2026
Vulnerability details
The vulnerability allows a remote attacker to modify server-side annotation data.
The vulnerability exists due to missing authorization in the /book-update-annotations endpoint when handling POST requests that merge and persist annotation JSON for a readable book. A remote attacker can send a specially crafted request to modify server-side annotation data.
Only books the caller is allowed to access can be targeted, and deployments with readonly users or anonymous network access are affected.