PT-2026-70359 · Unknown · Audiobookshelf
CVE-2026-73085
·
Published
2026-08-11
·
Updated
2026-08-11
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Audiobookshelf versions prior to 2.36.0
Description
The
jwtAuthCheck() function in server/auth/TokenManager.js incorrectly treats JSON Web Tokens (JWTs) of the refresh token type as bearer access tokens. This occurs on API and WebSocket resource endpoints, such as '/api/me', instead of restricting these tokens to the '/auth/refresh' endpoint. Consequently, refresh tokens can be used to authenticate as the associated users.Recommendations
Update to version 2.36.0.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Audiobookshelf