Missing Authentication Vulnerability in Podgrab by Podgrab Team
CVE-2026-104058

6.3MEDIUM

Key Information:

Vendor

Akhilrex

Status
Vendor
CVE Published:
1 October 2026

What is CVE-2026-104058?

Podgrab is affected by a missing authentication issue where the /ws WebSocket route is improperly registered on the root gin engine, rather than being secured by the BasicAuth-protected router group. This oversight enables unauthenticated network clients to connect, even when a PASSWORD is set. Consequently, attackers can join the allConnections set and intercept PlayerExists broadcasts containing identifiers supplied by legitimate clients. They can exploit this flaw to hijack queue payloads directed at authenticated users, gaining unauthorized access to sensitive information such as episode IDs, titles, and server-side file paths, thereby potentially disrupting normal playback experiences.

Affected Version(s)

podgrab 0 <= 032248091294dbf5b6a439a5afd93788a7cc647f

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mansur Mavlankulov
.