PT-2026-36731 · Crocodilestick · Calibre-Web-Automated

Jasperx

·

Published

2026-05-04

·

Updated

2026-05-04

·

CVE-2026-7713

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions crocodilestick Calibre-Web-Automated versions prior to 4.0.7
Description Improper authorization in the Kobo auth-token Route allows a remote attacker to manipulate the generate auth token() function within the cps/kobo auth.py file.
Recommendations Update to version 4.0.7.

Exploit

Fix

Improper Authorization

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2026-7713

Affected Products

Calibre-Web-Automated