PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Misconfiguration·Updated Aug 11, 2026

Audiobookshelf - Authentication Bypass

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.
Description

audiobookshelf's authentication-exemption check (server/routers/Auth.js) matches unauthenticated-allowed GET routes against req.path via a regex requiring a literal /items/:id/cover or /authors/:id/image shape, where req.path retains %2F sequences URL-encoded. CacheManager.handleCoverCache then joins this decoded value into a cache file path and streams the result before any database-backed ownership check.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
audiobookshelfby advplyr
2.19.1
Updated Sep 18, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Audiobookshelf - Authentication Bypass CVE-2026-71209 Scanner | S4E