Authorization bypass through user-controlled key in Kavita - #VU147280

 

Authorization bypass through user-controlled key in Kavita - #VU147280

Published: September 7, 2026


Vulnerability identifier: #VU147280
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to delete another user's collection.

The vulnerability exists due to authorization bypass through a user-controlled key in the POST /api/collection/update-series endpoint when processing a request containing another user's collection tag ID. A remote user can remove all series from another user's collection to delete another user's collection.

The collection is deleted only when removing the series empties it.


Affected software

Kavita

Remediation

Install security update from vendor's website.

Kavita - update to 0.9.1.0

External References

Related Security Bulletins