CVE-2026-93954 | grimmory-tools grimmory up to 3.3.3/3.4.1 Settings API Endpoint AppSettingController.java AppSettingController.getAppSettings authorization (Issue 2430)

SecurityVulns

A vulnerability categorized as problematic has been discovered in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect authorization.

This vulnerability is uniquely identified as CVE-2026-93954. The attack can be launched remotely. Moreover, an exploit is present.

Applying a patch is advised to resolve this issue.

PR #2558, merged as 53abc8b, moved the OIDC secret into a dedicated setting, but did not by itself restrict GET /api/v1/settings.VulDB Recent EntriesRead More