CVE 4.3 MEDIUM

Audiobookshelf: Collection endpoints bypass library access controls exposing restricted library data_CVE-2026-42884

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/collections and GET /api/collections/:id endpoints return collections from all libraries without checking whether the requesting user has access to each collection's library. An authenticated user with access to any library can enumerate and read collections (including full book metadata) from libraries they are explicitly restricted from accessing. This vulnerability is fixed in 2.32.2.

Basic Information

ID CVE-2026-42884
Source GitHub_M
Published May 11, 2026 at 19:52

Affected Product

Vendor advplyr
Product audiobookshelf
Version < 2.33.2
Affected Versions advplyr audiobookshelf < 2.33.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.