Description
A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-08-18
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper authentication flaw exists in the OAuth Sign-In component of karakeep, affecting versions up to 0.32.0. The vulnerability arises from an undisclosed function in apps/web/server/auth.ts that allows an attacker to bypass normal authentication checks. A successful exploit would grant the attacker access to the application under the victim’s identity, potentially exposing sensitive data and enabling further attacks such as privilege escalation or data tampering. The weakness is categorized as CWE‑287 (Improper Authentication).

Affected Systems

The flaw impacts the karakeep web application, specifically the OAuth Sign-In feature in karakeep-app:karakeep up to version 0.32.0. There are no other vendor or product groups reported as affected.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. Because the EPSS score is not available and the issue is not listed in CISA KEV, the current knowledge of exploitation likelihood is limited. The public disclosure and the reported difficulty of the exploit suggest that while the attack requires remote access and has a relatively high complexity, it is still considered difficult to execute. Nonetheless, the possibility of unauthorized access mandates timely remediation.

Generated by OpenCVE AI on August 18, 2026 at 12:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest karakeep release that contains the official fix for the authentication bypass
  • Audit and tighten OAuth callback handling to ensure only approved URLs are accepted
  • Implement enhanced monitoring of authentication attempts and review logs for anomalous activity

Generated by OpenCVE AI on August 18, 2026 at 12:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.
Title karakeep-app karakeep OAuth Sign-In auth.ts improper authentication
First Time appeared Karakeep-app
Karakeep-app karakeep
Weaknesses CWE-287
CPEs cpe:2.3:a:karakeep-app:karakeep:*:*:*:*:*:*:*:*
Vendors & Products Karakeep-app
Karakeep-app karakeep
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Karakeep-app Karakeep
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-18T11:15:09.946Z

Reserved: 2026-08-18T04:30:33.990Z

Link: CVE-2026-75774

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T12:19:32.380

Modified: 2026-08-18T12:19:32.380

Link: CVE-2026-75774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T12:30:04Z

Weaknesses