Improper Authorization in Janeczku Calibre-Web Endpoint Functionality
CVE-2026-7709
Key Information:
- Vendor
Janeczku
- Status
- Vendor
- CVE Published:
- 3 May 2026
Badges
What is CVE-2026-7709?
A significant vulnerability exists within the Janeczku Calibre-Web application, specifically in the Endpoint function located in the kobo_auth.py file. This flaw allows for unauthorized manipulation of the user_id argument in the generate_auth_token function, leading to improper authorization. Remote attackers can exploit this vulnerability, potentially gaining unauthorized access to user accounts. Despite attempts to inform the vendor, there has been no response regarding this issue. As the exploitation of this vulnerability is publicly accessible, it poses a serious risk to users of the affected versions.
Affected Version(s)
Calibre-Web 0.6.0
Calibre-Web 0.6.1
Calibre-Web 0.6.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
