Junglewise Threat Intelligence

CVE-2026-90941: novel-plus authorization bypass in BookController download endpoint

CVE-2026-90941 · Severity: medium · CVSS 4.3 · Published 2026-09-14

Technologies: Novel-Plus.

Executive brief

novel-plus is an open-source novel reading CMS system with subscription and VIP features. An authenticated attacker with backend admin access can bypass permission checks in the book download endpoint to export complete books including paid chapters without triggering VIP or purchase verification, undermining the subscription revenue model and exposing paid content.

Technical details

The BookController download endpoint in novel-plus through version 5.3.3 fails to enforce proper authorization checks on book content retrieval. An authenticated backend admin can supply a bookId and bookName parameter to retrieve all chapter content, including premium/paid chapters, bypassing the VIP status verification and purchase authorization checks that are enforced elsewhere in the application. The vulnerability requires valid backend authentication and allows complete book text export. A patch or update beyond version 5.3.3 is needed to add proper permission validation in the download endpoint.

Affected products

  • novel-plus novel-plus through 5.3.3

Timeline

  • 2026-09-14: disclosed

References