
CVE-2026-47202 Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for … https://www.cve.org/CVERecord?id=CVE-2026-47202
Post summary
Kavita’s older versions contain an improper token validation flaw that lets unauthenticated actors request JWTs; the vulnerability is disclosed via its CVE record.
