Authorization bypass through user-controlled key in Kavita - #VU147278
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to alter another user's dashboard or side-navigation widget visibility.
The vulnerability exists due to authorization bypass through a user-controlled key in the dashboard and side-navigation stream update handlers when processing user-supplied stream identifiers. A remote user can submit identifiers for streams owned by another user to alter their visibility.
The bulk side-navigation visibility endpoint can alter all supplied side-navigation streams in a single request.