CVE-2026-47202
Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given knowledge of their username. This vulnerability is fixed in 0.9.0.2.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/Kareadita/Kavita/releases/tag/v0.9.0.2, https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47202.json, https://github.com/Kareadita/Kavita/security/advisories/GHSA-m2v3-fcjh-hm22, https://nvd.nist.gov/vuln/detail/CVE-2026-47202