Authorization bypass through user-controlled key in Kavita - #VU147284

 

Authorization bypass through user-controlled key in Kavita - #VU147284

Published: September 7, 2026


Vulnerability identifier: #VU147284
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose file sizes of series, volumes, and chapters in restricted libraries.

The vulnerability exists due to authorization bypass through user-controlled key in the `bulk-volume-size`, `bulk-chapter-size`, and `bulk-series-size` endpoints when processing POST requests containing user-supplied entity ID arrays. A remote user can submit arbitrary series, volume, or chapter IDs to disclose file sizes of restricted entities.

The account must have the Download role.


Affected software

Kavita

Remediation

Install security update from vendor's website.

Kavita - update to 0.9.1.0

External References

Related Security Bulletins