Authorization Flaw in Kavita Reading Server Exposes User Content
CVE-2026-44776
5.9MEDIUM
What is CVE-2026-44776?
Kavita, a cross-platform reading server, contains a vulnerability that allows low-privileged users to access content from libraries they are not authorized to view. Prior to version 0.9.0, several endpoints such as download and metadata endpoints do not adequately enforce library-level authorization controls. This oversight enables users who can predict certain identifiers (chapterId, volumeId, seriesId) to download files, check their sizes, and receive metadata for protected content. This issue has been resolved in version 0.9.0.
Affected Version(s)
Kavita < 0.9.0
