CVE-2026-96880: TaleLin lin-cms-spring-boot book Endpoint BookController.java getBook improper authorization
A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/main/java/io/github/talelin/latticy/controller/v1/BookController.java of the component book Endpoint. Performing a manipulation of the argument ID results in improper authorization. The attack is possible to be carried out remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
TaleLin lin-cms-spring-boot versions up to and including 0.2.1 are identified as affected, specifically the book endpoint's getBook function in BookController.java.
What does an attacker need to exploit this issue?
The issue can be exploited remotely without authentication or user interaction by manipulating the ID argument supplied to the book endpoint.
What is the likely impact?
Successful exploitation can expose book data that the requester is not authorized to access. The provided severity vector indicates confidentiality impact only, with no stated integrity or availability impact.
Is public exploit information available?
Yes. The exploit has been made public and could be used.