Web Server Configuration Vulnerability in MyBooks by PoxenStudio
CVE-2026-45273

8.7HIGH

Key Information:

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-45273?

MyBooks, an ebook management web server developed by PoxenStudio, contains a vulnerability within its AdminSettings.post handler, which allows authenticated regular users to manipulate server configuration settings without proper permissions. This oversight results from a missing check on the self.admin_user property, permitting unauthorized changes to critical aspects such as SMTP credentials, OAuth client secrets, and security feature flags. Additionally, the flawed authentication process fails to prevent registered but unactivated accounts from accessing the vulnerable handler. Successful exploitation can lead to unauthorized disclosure of sensitive information, disruption of application functionality, service interruptions, and potential code-injection attacks. This vulnerability is addressed in version 3.42.0.

Affected Version(s)

talebook < 3.42.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.