CVE-2026-51876: DeepTutor DeepTutor vulnerability
DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a publicly exposed bookid to submit a confirm-proposal request for an existing book, causing unauthorized overwrites of persisted metadata and spine content.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
DeepTutor 1.4.0 deployments are exposed if the book confirmation flow is reachable by callers that are unauthenticated or lack authorization, and a valid publicly exposed book_id can be obtained.
What does an attacker need to exploit it?
An attacker needs a publicly exposed book_id for an existing book and the ability to submit a confirm-proposal request. No authentication or authorization is required by the affected flow.
What is the impact of successful exploitation?
A successful attacker can overwrite persisted metadata and spine content for an existing book.