CVE-2026-93954 | grimmory-tools grimmory up to 3.3.3/3.4.1 Settings API Endpoint AppSettingController.java AppSettingController.getAppSettings authorization (Issue 2430)
A vulnerability categorized as problematic has been discovered in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect authorization.
This vulnerability is uniquely identified as CVE-2026-93954. The attack can be launched remotely. Moreover, an exploit is present.
Applying a patch is advised to resolve this issue.
PR #2558, merged as 53abc8b, moved the OIDC secret into a dedicated setting, but did not by itself restrict GET /api/v1/settings.VulDB Recent EntriesRead More