Retour aux alertes CVE
CVE-2026-75774 LOW CVSS 3.7

CVE-2026-75774 LOW

Publiée 2 weeks ago Fiche NVD officielle

Qu'est-ce que c'est ?

Résumé

Une faille d'authentification incorrecte touche le module de connexion OAuth dans le fichier apps/web/server/auth.ts de l'application karakeep jusqu'à la version 0.32.0. Un attaquant distant peut potentiellement contourner le mécanisme d'authentification pour usurper des comptes utilisateurs, bien que l'attaque soit complexe à réaliser.

A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Technologies affectées

Non précisé par la fiche NVD.

Recommandation

Désactivez temporairement la fonctionnalité de connexion OAuth ou restreignez l'accès à l'application via un réseau privé en attendant la publication d'un correctif officiel supérieur à la version 0.32.0.

Généré automatiquement à partir de la description CVE -- vérifie les références officielles avant d'agir.

Exploits publics connus (0)

Aucun proof-of-concept public trouvé sur GitHub à ce jour. Ça peut changer : les PoC sont souvent publiés plusieurs jours ou semaines après la divulgation.