Junglewise Threat Intelligence

CVE-2026-44775: Kavita missing authentication in ReaderController image endpoint

CVE-2026-44775 · Severity: info · CVSS 6.9 · Published 2026-05-26

Technologies: Kareadita Kavita. Vendors: Kareadita.

Executive brief

Kavita is a digital library server used for hosting and reading comics, manga, and books. A security flaw allows anyone with network access to view and download every page of every book in the library without logging in. Because the system uses simple sequential numbers to identify content, an attacker can easily automate the theft of the entire library's contents.

Technical details

The `ReaderController.GetImage` endpoint in Kavita (prior to 0.9.0) is decorated with the `[AllowAnonymous]` attribute, bypassing standard authentication requirements. Although the endpoint accepts an `apiKey` parameter, the application fails to validate it, accepting any arbitrary string. Because chapter and page IDs are sequential integers, an unauthenticated attacker can perform a Broken Object Level Authorization (BOLA) attack to enumerate and retrieve all images across all libraries. The vulnerability is rooted in the lack of both authentication and library-level authorization checks within the `GetImage` method. This was resolved in version 0.9.0 by implementing proper authentication and access controls.

Affected products

  • Kareadita Kavita < 0.9.0

Timeline

  • 2026-05-05: advisory: GitHub Security Lab published advisory GHSA-6gc9-6r8p-5wg2
  • 2026-05-26: disclosed: CVE-2026-44775 published to NVD
  • 2026-05-26: patched: Vulnerability fixed in version 0.9.0

References

Related threats