Authorization bypass through user-controlled key in Kavita - #VU147285
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to disclose other users' bookmarked page images.
The vulnerability exists due to authorization bypass through user-controlled key in the /api/download/bookmarks endpoint when processing user-supplied bookmark and series identifiers. A remote user can submit another user's bookmark identifier paired with a series identifier they can access to disclose other users' bookmarked page images.
Bookmark identifiers are sequential auto-incrementing integers, enabling their enumeration.