Authentication Flaw in Crocodilestick Calibre-Web-Automated Affects Remote Management
CVE-2026-7714
Key Information:
- Vendor
Crocodilestick
- Status
- Vendor
- CVE Published:
- 4 May 2026
Badges
What is CVE-2026-7714?
An authentication flaw has been identified in the Admin Endpoint of Crocodilestick's Calibre-Web-Automated within the file cps/cwa_functions.py. This vulnerability allows remote attackers to manipulate the application due to inadequate authentication mechanisms. As a result, unauthorized users may exploit this weakness to gain access to protected functionalities without appropriate credentials. Despite prior warnings through a pull request, the project's maintainers have yet to address the issue, which raises concerns about the software's security posture.
Affected Version(s)
Calibre-Web-Automated 4.0.0
Calibre-Web-Automated 4.0.1
Calibre-Web-Automated 4.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
