PT-2026-36742 · Crocodilestick · Calibre-Web-Automated

Jasperx

·

Published

2026-05-04

·

Updated

2026-05-04

·

CVE-2026-7714

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions crocodilestick Calibre-Web-Automated versions prior to 4.0.7
Description A flaw in the Admin Endpoint component, specifically within the cps/cwa functions.py file, allows for missing authentication. This issue enables a remote attacker to bypass authentication mechanisms.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-7714

Affected Products

Calibre-Web-Automated