Unauthorized Book Annotation Changes in Calibre e-Book Manager
CVE-2026-73249
7.5HIGH
What is CVE-2026-73249?
The Calibre e-book manager is exposed to a vulnerability that enables unauthorized changes to book annotations. Prior to version 9.12.0, the Content Server endpoint mishandles database write access permissions, allowing both unauthenticated and read-only users to submit attacker-controlled JSON data via the '/book-update-annotations/{library_id}/{book_id}/{fmt}' endpoint. This flaw bypasses necessary access checks, resulting in potential unauthorized persistence of changes to book annotations. Users are advised to update their installations to version 9.12.0 or later to mitigate this risk.
Affected Version(s)
calibre < 9.12.0
