Description
A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 2b66ca6df8110f6b512e030b54c16b9fbe318f17. Applying a patch is advised to resolve this issue. PR #2558, merged as 53abc8b, moved the OIDC secret into a dedicated setting, but did not by itself restrict GET /api/v1/settings.
Published: 2026-09-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

A flaw in grimmory’s Settings API endpoint, specifically the AppSettingController.getAppSettings function, allows an attacker to bypass normal authorization checks. This incorrect authorization can grant unauthorized users access to application settings data or functionality that should be protected, potentially enabling further exploitation of the system.

Affected Systems

The vulnerability affects grimmory-tools’ grimmory component versions up to 3.3.3 and 3.4.1. It is present in the backend module located in backend/src/main/java/org/booklore/controller/AppSettingController.java and impacts the GET /api/v1/settings interface.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, but the exploit has been publicly disclosed and can be launched remotely. Attackers can use the exposed endpoint to read or modify configuration settings, potentially escalating privileges or compromising the application’s security posture.

Generated by OpenCVE AI on September 19, 2026 at 23:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch identified by commit 2b66ca6df8110f6b512e030b54c16b9fbe318f17 to correct the authorization logic in AppSettingController.getAppSettings.
  • After patching, ensure that the GET /api/v1/settings endpoint is protected by role‑based access controls or an explicit authorization check so that only users with the required permissions can call it.
  • Verify that the OIDC secret has been moved to a dedicated setting and that no unprotected configuration files or environment variables expose sensitive data.
  • If an immediate patch cannot be applied, block or restrict the /api/v1/settings endpoint from untrusted clients using firewall rules or reverse‑proxy access controls as a temporary safeguard.

Generated by OpenCVE AI on September 19, 2026 at 23:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 2b66ca6df8110f6b512e030b54c16b9fbe318f17. Applying a patch is advised to resolve this issue. PR #2558, merged as 53abc8b, moved the OIDC secret into a dedicated setting, but did not by itself restrict GET /api/v1/settings.
Title grimmory-tools grimmory Settings API Endpoint AppSettingController.java AppSettingController.getAppSettings authorization
First Time appeared Grimmory-tools
Grimmory-tools grimmory
Weaknesses CWE-285
CWE-863
CPEs cpe:2.3:a:grimmory-tools:grimmory:*:*:*:*:*:*:*:*
Vendors & Products Grimmory-tools
Grimmory-tools grimmory
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Grimmory-tools Grimmory
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:43:56.136Z

Reserved: 2026-09-19T08:51:12.177Z

Link: CVE-2026-93954

cve-icon Vulnrichment

Updated: 2026-09-22T15:30:24.934Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T22:16:28.453

Modified: 2026-09-22T16:18:14.737

Link: CVE-2026-93954

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:45:16Z

Weaknesses