Information Disclosure in Audiobookshelf: Self-Hosted Audiobook and Podcast Server
CVE-2026-42884

4.3MEDIUM

Key Information:

Vendor

Advplyr

Vendor
CVE Published:
11 May 2026

What is CVE-2026-42884?

Audiobookshelf, a self-hosted audiobook and podcast server, contains a flaw in its endpoint permissions. Specifically, prior to version 2.32.2, the GET /api/collections and GET /api/collections/:id endpoints exposed collection data from all libraries without proper access validation. This oversight allows authenticated users to view collections they should not have permissions for, including detailed metadata about books from restricted libraries. The issue has been addressed in version 2.32.2, enhancing the security protocol to ensure users can only access collections pertinent to their permissions.

Affected Version(s)

audiobookshelf < 2.33.2

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.