CVE-2026-93955
4.3 MEDIUMpublic exploit availablePublished 2026-09-19 · Updated 2026-09-21
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component Download Endpoint. Performing a manipulation of the argument bookId results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. Issue #2431 is closed as completed, but its only comment states that the issue “has already been reported elsewhere.” No fixing commit or pull request is identified there.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weaknesses
CWE-285, CWE-639
Public exploit & PoC references
All references
- https://github.com/grimmory-tools/grimmory/
- https://github.com/grimmory-tools/grimmory/issues/2431
- https://github.com/grimmory-tools/grimmory/issues/2431#issuecomment-5384402858
- https://vuldb.com/cve/CVE-2026-93955
- https://vuldb.com/submit/943921
- https://vuldb.com/vuln/407914
- https://vuldb.com/vuln/407914/cti
- https://github.com/grimmory-tools/grimmory/issues/2431#issuecomment-5384402858
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2026-18818
- MEDIUMCVE-2026-79917PoC
- MEDIUMCVE-2026-94152PoC
- MEDIUMCVE-2025-71420PoC
- MEDIUMCVE-2026-11454
- MEDIUMCVE-2026-12995
- LOWCVE-2026-16070
- LOWCVE-2026-16746
Related by shared AI tags and CWE weakness class. Browse the full archive.