NONE · 0

CVE-2026-47202

Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given kn...

Vulnerability Description

Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given knowledge of their username. This vulnerability is fixed in 0.9.0.2.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-47202?

CVE-2026-47202 is a documented vulnerability. Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given kn...

How severe is CVE-2026-47202?

CVSS scoring is not yet available for CVE-2026-47202. Check NVD for updates.

Is there a patch for CVE-2026-47202?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.