VYPR
Critical severityNVD Advisory· Published May 26, 2026· Updated May 26, 2026

CVE-2026-47202

CVE-2026-47202

Description

Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given knowledge of their username. This vulnerability is fixed in 0.9.0.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An improper token validation flaw in Kavita prior to 0.9.0.2 allows unauthenticated attackers to obtain JWTs for any user, including admins, leading to account takeover.

Vulnerability

In Kavita versions prior to 0.9.0.2, the token validation logic is improperly implemented, allowing a remote and unauthenticated attacker to request a JSON Web Token (JWT) for any user, including administrators, provided they know the target's username. The underlying weaknesses are classified as CWE-287 (Improper Authentication), CWE-345 (Insufficient Verification of Data Authenticity), and CWE-697 (Incorrect Comparison) [2]. The vulnerability was confirmed in container images ghcr.io/kareadita/kavita:0.9.0 and 0.8.9.1 [2].

Exploitation

An attacker needs only knowledge of a valid username (no authentication or user interaction required). By sending a crafted request to the token endpoint, the attacker can obtain a valid JWT for that user [2]. The attack is remote and does not require any prior access or special network position.

Impact

Successful exploitation grants the attacker a valid JWT for the targeted user, enabling full account takeover. For administrative accounts, this results in complete compromise of the Kavita instance, including access to all reading lists, series, and user data. The vulnerability is rated Critical with a CVSSv4 score of 9.3 [2].

Mitigation

The vulnerability is fixed in Kavita version 0.9.0.2, released on 2026-05-26 [1]. All users are strongly advised to update immediately. No workarounds have been published, and the issue is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Kareadita/Kavitareferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <0.9.0.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.