Description
A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component Download Endpoint. Performing a manipulation of the argument bookId results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. Issue #2431 is closed as completed, but its only comment states that the issue “has already been reported elsewhere.” No fixing commit or pull request is identified there.
Published: 2026-09-19
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization Bypass (CWE-285, CWE-639)
Action: Patch Now
AI Analysis

Impact

Grimmory Tools' Download Endpoint, specifically the streamFileToResponse method in KoboController.java, has a flaw that allows an attacker to manipulate the bookId parameter. This manipulation bypasses the intended authorization checks, enabling the remote attacker to request and receive any file that the application can access. The weakness corresponds to CWE-285 and CWE-639. Because the vulnerability is triggered via standard HTTP requests, based on the description it is inferred that the attacker does not require any special credentials or local privileges, resulting in unauthorized data exposure.

Affected Systems

Vulnerable releases include grimmory-tools Grimmory versions up to 3.3.3 and 3.4.1. These versions are hosted under the Grimmory Tools project on GitHub and are commonly used in environments that expose the KoboController download functionality. No higher‑version fix has been documented in the public record, so all instances of the mentioned releases remain at risk unless addressed.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, but the lack of an EPSS rating combined with an active public exploit increases the practical risk. Because the attack vector is remote and the vulnerability can be triggered through normal web traffic, it is feasible for an attacker who does not require prior authentication to compromise the confidentiality of stored files; based on the description it is inferred that the attacker does not need genuine credentials. The issue is not listed in the CISA KEV catalog, yet the public availability of the exploit suggests a higher likelihood of real‑world attacks than the raw score implies.

Generated by OpenCVE AI on September 19, 2026 at 23:57 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Grimmory to the latest available release that reinstates the authorization check for streamFileToResponse; if no public fix is available, coordinate with the maintainers to obtain a patch.
  • Limit access to the Download Endpoint by configuring the web server or application firewall to allow only trusted IP addresses, thereby reducing the attack surface.
  • Review and modify the streamFileToResponse code to enforce a strict authorization check that validates the requesting user against the requested bookId, implementing appropriate role‑based access control.
  • Enable detailed logging for all download attempts and set up alerts for repeated or suspicious unauthorized access patterns to facilitate rapid detection and response.

Generated by OpenCVE AI on September 19, 2026 at 23:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the function streamFileToResponse of the file backend/src/main/java/org/booklore/controller/KoboController.java of the component Download Endpoint. Performing a manipulation of the argument bookId results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. Issue #2431 is closed as completed, but its only comment states that the issue “has already been reported elsewhere.” No fixing commit or pull request is identified there.
Title grimmory-tools grimmory Download Endpoint KoboController.java streamFileToResponse authorization
First Time appeared Grimmory-tools
Grimmory-tools grimmory
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:grimmory-tools:grimmory:*:*:*:*:*:*:*:*
Vendors & Products Grimmory-tools
Grimmory-tools grimmory
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Grimmory-tools Grimmory
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T20:20:23.567Z

Reserved: 2026-09-19T08:51:16.505Z

Link: CVE-2026-93955

cve-icon Vulnrichment

Updated: 2026-09-21T20:12:56.815Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T23:17:09.077

Modified: 2026-09-21T21:17:20.133

Link: CVE-2026-93955

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:45:16Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key