Incorrect authorization in Kavita - #VU147277
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose shared annotation content.
The vulnerability exists due to incorrect authorization in the annotation read endpoints when processing requests for shared annotations. A remote user can request annotations for a chapter, annotation, or series outside their authorized library or age restrictions to disclose shared annotation content.
Exploitation requires annotation sharing to be enabled; it is disabled by default.