CVE-2026-7709Disclosure

LOWCVSS 2.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in janeczku Calibre-Web up to 0.6.26. The impacted element is the function generate_auth_token of the file cps/kobo_auth.py of the component Endpoint. Such manipulation of the argument user_id leads to improper authorization. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-266CWE-285

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-03: 3Technical Details · 2026-05-03: 305-03
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-7709 A vulnerability was identified in janeczku Calibre-Web up to 0.6.26. The impacted element is the function generate_auth_token of the file cps/kobo_auth.py of the compon… https://www.cve.org/CVERecord?id=CVE-2026-7709 ----- Traducción: CVE-2026-7709 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑7709 as a vulnerability in Calibre‑Web, detailing the affected function but providing no PoC, exploit code, or patch information.

    0000021
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-7709 A vulnerability was identified in janeczku Calibre-Web up to 0.6.26. The impacted element is the function generate_auth_token of the file cps/kobo_auth.py of the compon… https://www.cve.org/CVERecord?id=CVE-2026-7709

    Post summary

    CVE-2026-7709 was disclosed affecting Calibre-Web up to 0.6.26, specifically the generate_auth_token function.

    00000217
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-7709 Improper Authorization in janeczku Calibre-Web 0.6.26 Endpoint https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-7709

    Post summary

    CVE-2026-7709 identifies an improper authorization issue in Calibre-Web 0.6.26; no PoC, exploit, patch, or active exploitation details are provided.

    0000034
    4.0K followersView on X

Explore more