Authorization bypass through user-controlled key in Kavita - #VU147280
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to delete another user's collection.
The vulnerability exists due to authorization bypass through a user-controlled key in the POST /api/collection/update-series endpoint when processing a request containing another user's collection tag ID. A remote user can remove all series from another user's collection to delete another user's collection.
The collection is deleted only when removing the series empties it.