CVE-2026-30975Disclosure(sonarr / sonarr)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch sonarr sonarr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for local addresses (Authentication Required set to: `Disabled for Local Addresses`) without a reverse proxy running in front of Sonarr that didn't not pass through the invalid header. Patches are available in version 4.0.16.2942 in the nightly/develop branch and version 4.0.16.2944 for stable/main releases. Some workarounds are available. Make sure Sonarr's Authentication Required setting is set to `Enabled`, run Sonarr behind a reverse proxy, and/or do not expose Sonarr directly to the internet and instead rely on accessing it through a VPN, Tailscale or a similar solution.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sonarr

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-26)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
sonarr

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-25: 1Mentions · 2026-03-26: 2Patch / Workaround · 2026-03-26: 1Technical Details · 2026-03-25: 1Technical Details · 2026-03-26: 203-2503-26
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-251
Disclosure1
2026-03-262
Disclosure2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30975 Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for … https://www.cve.org/CVERecord?id=CVE-2026-30975

    Post summary

    The tweet announces CVE‑2026‑30975, noting an authentication bypass affecting Sonarr versions before 4.0.16.2942, with no PoC, exploit, or active exploitation claims, but implicitly encouraging an update to the patched version.

    00010190
    56.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30975 Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for … https://www.cve.org/CVERecord?id=CVE-2026-30975 ----- Traducción: CVE-2026-30975 Son… http://infoflow.cloud`

    Post summary

    The post reveals an authentication bypass vulnerability (CVE‑2026‑30975) in Sonarr before version 4.0.16.2942 and provides a link to the official CVE record.

    0000030
    61 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-30975 - High Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for local addresses (Authenti... https://www.thehackerwire.com/vulnerability/CVE-2026-30975/ https://t.co/BJOuBc1OZ6

    Post summary

    An authentication bypass vulnerability (CVE-2026-30975) for Sonarr versions earlier than 4.0.16.2942 was disclosed; the post includes basic technical details but no PoC, exploitation, or patch information.

    0000047
    145 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsonarrsonarr---

Explore more