๐Ÿ” CVE Alert

CVE-2026-93954

MEDIUM 4.3

grimmory-tools grimmory Settings API Endpoint AppSettingController.java AppSettingController.getAppSettings authorization

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 2b66ca6df8110f6b512e030b54c16b9fbe318f17. Applying a patch is advised to resolve this issue. PR #2558, merged as 53abc8b, moved the OIDC secret into a dedicated setting, but did not by itself restrict GET /api/v1/settings.

CWE CWE-863 CWE-285
Vendor grimmory-tools
Product grimmory
Published Sep 19, 2026
Stay Ahead of the Next One

Get instant alerts for grimmory-tools grimmory

Be the first to know when new medium vulnerabilities affecting grimmory-tools grimmory are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

grimmory-tools / grimmory
3.3.0 3.3.1 3.3.2 3.3.3 3.4.0 3.4.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/407913 vuldb.com: https://vuldb.com/vuln/407913/cti vuldb.com: https://vuldb.com/cve/CVE-2026-93954 vuldb.com: https://vuldb.com/submit/943919 github.com: https://github.com/grimmory-tools/grimmory/issues/2430 github.com: https://github.com/grimmory-tools/grimmory/pull/2647 github.com: https://github.com/grimmory-tools/grimmory/commit/2b66ca6df8110f6b512e030b54c16b9fbe318f17 github.com: https://github.com/grimmory-tools/grimmory/

Credits

๐Ÿ” summmm (VulDB User) VulDB CNA Team