CacheManager.handleCoverCache of the file server/routers/Auth.js of the component Authentication Exemption Check. The manipulation of the argument ID results in information disclosure.
This vulnerability is identified as CVE-2026-71209. The attack can be executed remotely. There is not any exploit available.
Intelligence View
⚡ tsecurity.de Intelligence
CVE-2026-71209 | advplyr audiobookshelf up to 2.35.1 Authentication Exemption Check server/routers/Auth.js CacheManager.handleCoverCache ID information disclosure (EUVD-2026-53206)
A vulnerability classified as problematic was found in advplyr audiobookshelf up to 2.35.1. The affected element is the function
SOCIAL SHARE CARD GENERATOR