No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.36.0, the jwtAuthCheck function in server/auth/TokenManager.js treats JWTs with the refresh token type as bearer access tokens on API and WebSocket resource endpoints such as /api/me instead of restricting them to /auth/refresh, allowing refresh tokens to authenticate as the associated users. This issue is fixed in version 2.36.0. | |
| Title | Audiobookshelf: Refresh Token Accepted on Resource Endpoints | |
| Weaknesses | CWE-287 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-11T18:39:19.953Z
Reserved: 2026-08-10T19:37:41.445Z
Link: CVE-2026-73085
Updated: 2026-08-11T18:39:15.412Z
Status : Received
Published: 2026-08-11T17:19:16.557
Modified: 2026-08-11T19:18:51.163
Link: CVE-2026-73085
No data.
OpenCVE Enrichment
No data.
-
CWE-287
Improper Authentication