What is CVE-2026-73249?
CVE-2026-73249 is a critical vulnerability in calibre's Content Server, affecting versions prior to 9.12.0. The /book-update-annotations endpoint fails to enforce write access checks, potentially allowing an unauthenticated attacker to modify file annotations. Immediate update to version 9.12.0 or later is strongly recommended.
Azərbaycanca: CVE-2026-73249, calibre e-kitab menecerinin Məzmun Serverində aşkarlanmış kritik bir zəiflikdir. 9.12.0 versiyasından əvvəlki versiyalarda, /book-update-annotations endpoint-i yazma icazə yoxlamasını düzgün aparmır ki, bu da autentifikasiya olunmamış hücumçunun fayl annotasiyalarını dəyişdirməsinə imkan verə bilər. Təsirə məruz qalan sistemlərdə dərhal 9.12.0 və ya daha yuxarı versiyaya yeniləmə aparmaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What exactly is the CVE-2026-73249 vulnerability?
It is a critical vulnerability in calibre's Content Server, affecting versions prior to 9.12.0. The /book-update-annotations endpoint fails to enforce write access checks, potentially allowing an unauthenticated attacker to modify file annotations.
How can I protect against CVE-2026-73249?
It is strongly recommended to immediately update to calibre version 9.12.0 or later on affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.