CVE-2026-26065Disclosure(calibre-ebook / calibre)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch calibre-ebook calibre systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-byte and 202-byte header variants) that allow arbitrary file writes with arbitrary extension and arbitrary content anywhere the user has write permissions. Files are written in 'wb' mode, silently overwriting existing files. This can lead to potential code execution and Denial of Service through file corruption. This issue has been fixed in version 9.3.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • calibre

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-20); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
calibre

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-20: 4Mentions · 2026-02-24: 1Mentions · 2026-02-25: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-24: 1Technical Details · 2026-02-20: 4Technical Details · 2026-02-24: 1Technical Details · 2026-02-25: 102-2002-2402-25
Signal classification2 categories
Disclosure
466.7%
Patch
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-204
Disclosure3Patch1
2026-02-241
Patch1
2026-02-251
Disclosure1
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26065 Path Traversal in Calibre E-Book Manager Allows Arbitrary File Writes https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26065

    Post summary

    This post announces CVE-2026-26065, a path traversal flaw in Calibre E‑Book Manager enabling arbitrary file writes, without providing any PoC, exploit code, active exploitation evidence, or patch details.

    0001045
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26065 (CVSS:9.3, HIGH) is Analyzed. calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and ..https://nvd.nist.gov/vuln/detail/CVE-2026-26065 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-26065, noting its high CVSS score and that it affects calibre versions 9.2.1 and later, but provides no details on exploitation or mitigation.

    0000036
    172 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `calibre` versions below 9.3.0 are vulnerable to path traversal (UBUNTU-CVE-2026-26065) when processing PDB files, potentially allowing arbitrary file access. Remediation involves updating. #calibre #PathTraversal #infosec https://www.pulsepatch.io/posts/ubuntu-cve-2026-26065-calibre-path-traversal-vulnerability

    Post summary

    Calibre versions below 9.3.0 are vulnerable to a path traversal flaw (CVE-2026-26065) that could allow arbitrary file access; users should update to mitigate.

    0000054
    1 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-26065 - High calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-by... https://www.thehackerwire.com/vulnerability/CVE-2026-26065/ https://t.co/RiJ4aZgFu6

    Post summary

    The text announces a path traversal vulnerability in Calibre 9.2.1 and earlier, linking to a vulnerability article, but does not present PoC, exploit code, active exploitation, or patch information.

    0000032
    112 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26065 calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through… https://www.cve.org/CVERecord?id=CVE-2026-26065

    Post summary

    CVE-2026-26065 enables a path traversal attack against Calibre 9.2.1 and older.

    0000072
    56.4K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: Path traversal in calibre <9.3.0 (CVE-2026-26065) lets attackers write files anywhere the user can, risking code execution & DoS. Upgrade now! 🛡️ https://radar.offseq.com/threat/cve-2026-26065-cwe-22-improper-limitation-of-a-pat-53326093 #OffSeq #Vulnerability #Cal... https://t.co/t2V0uTABQv

    Post summary

    The tweet alerts users to a critical path‑traversal flaw in Calibre versions under 9.3 that can lead to code execution or denial of service, and urges upgrading to remediate the issue.

    0000039
    265 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcalibre-ebookcalibre---

Explore more