CVE-2026-30976Disclosure(sonarr / sonarr)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch sonarr sonarr systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file readable by the Sonarr process. These include application configuration files (containing API keys and database credentials), Windows system files, and any user-accessible files on the same drive This issue only impacts Windows systems; macOS and Linux are unaffected. Files returned from the API were not limited to the directory on disk they were intended to be served from. This problem has been patched in 4.0.17.2950 in the nightly/develop branch or 4.0.17.2952 for stable/main releases. It's possible to work around the issue by only hosting Sonarr on a secure internal network and accessing it via VPN, Tailscale or similar solution outside that network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sonarr

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-25); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
sonarr

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-26: 2Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 203-2503-26
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-252
Disclosure1Patch1
2026-03-262
Disclosure2
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30976 Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file … https://www.cve.org/CVERecord?id=CVE-2026-30976

    Post summary

    CVE-2026-30976 is a remote file read vulnerability affecting Sonarr 4.x versions prior to 4.0.17.2950. No PoC, exploit code, active exploitation, or patch information is provided.

    00010179
    56.8K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30976 Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file … https://www.cve.org/CVERecord?id=CVE-2026-30976 ----- Traducción: CVE-2026-30976 Son… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-30976, noting that unauthenticated remote attackers may read any file in Sonarr versions prior to 4.0.17.2950, without providing PoC, exploit code, or evidence of active exploitation.

    0000029
    61 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-30976: HIGH] Critical vulnerability in Sonarr versions before 4.0.17.2950 allows remote unauthenticated attackers on Windows systems to access sensitive files. Update to patched versions immediately.#cve,CVE-2026-30976,#cybersecurity https://cvefind.com/CVE-2026-30976

    Post summary

    Critical Sonarr vulnerability (CVE-2026-30976) is disclosed with an immediate patch recommended; no PoC or active exploitation is referenced.

    0000075
    605 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-30976 - High Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file readable by the Sonarr pr... https://www.thehackerwire.com/vulnerability/CVE-2026-30976/ https://t.co/RIX1fNRGmH

    Post summary

    High‑severity arbitrary file‑read vulnerability disclosed for Sonarr versions prior to 4.0.17.2950; no PoC, exploit, active attack, or patch information is provided in the text.

    0000060
    145 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsonarrsonarr---

Explore more