Junglewise Threat Intelligence

CVE-2026-93954: grimmory Settings API authorization bypass

CVE-2026-93954 · Severity: medium · CVSS 4.3 · Published 2026-09-19

Technologies: Grimmory-Tools Grimmory. Vendors: Grimmory-Tools.

Executive brief

Grimmory is a self-hosted digital library application for organizing ebooks, comics, and audiobooks. A flaw in the Settings API endpoint allows unauthenticated or unauthorized users to access sensitive configuration data, including OIDC secrets, that should be restricted to administrators. An attacker with network access could retrieve these secrets and use them to compromise the application or bypass authentication mechanisms.

Technical details

An authorization check is missing in the GET /api/v1/settings endpoint of the AppSettingController, allowing the endpoint to be queried without proper permission validation. While a previous change moved the OIDC secret into a dedicated setting, the endpoint itself was not restricted, leaving sensitive settings accessible to any remote caller. The vulnerability has been patched and the fix is available in commit 2b66ca6df8110f6b512e030b54c16b9fbe318f17.

Affected products

  • grimmory-tools grimmory up to 3.3.3 and 3.4.1

Timeline

  • 2026-09-19: disclosed
  • 2026-09-18: patched: Patch commit 2b66ca6df8110f6b512e030b54c16b9fbe318f17 (PR #2647)

References

Related threats