Sceawere

Vulnerability Detail

CVE-2026-75774UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Karakeep OAuth Sign-In Improper Authentication

Vulnerability Metadata

Severity
Low
Score / CVSS
3.7
Creation Date
3h ago
Vendor
karakeep-app
Product
karakeep
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

A vulnerability was determined in karakeep-app karakeep up to 0.32.0. The impacted element is an unknown function of the file apps/web/server/auth.ts of the component OAuth Sign-In. This manipulation causes improper authentication. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is regarded as difficult. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.7",
  "pubDate": "2026-08-18T12:19:32.380Z",
  "pubdate": "2026-08-18T12:19:32.380Z",
  "executiveSummary": "An improper authentication vulnerability has been identified in the karakeep-app karakeep product up to version 0.32.0, specifically residing within the OAuth Sign-In component.\nThe flaw stems from insecure handling within an unknown function located in the apps/web/server/auth.ts file.\nThis security defect allows remote threat actors to bypass proper authentication mechanisms, potentially leading to unauthorized access and session manipulation.\nAlthough the attack complexity is assessed as rather high and the overall exploitability is considered difficult, a public exploit has already been disclosed, increasing operational risk.\nThe vendor was notified via an early issue report but has not yet provided an official response or patched build.\nOrganizations deploying vulnerable instances face potential compromise of user sessions and protected resources if attackers successfully execute the remote attack vector.",
  "technicalDetails": "The vulnerability resides in the OAuth Sign-In implementation handled by the apps/web/server/auth.ts file within the karakeep-app karakeep codebase, affecting all versions up to 0.32.0.\nThe root cause involves improper authentication logic during the OAuth protocol exchange, where identity verification or token validation routines fail to adequately enforce strict cryptographic checks or state parameter validations.\nBecause the vulnerable component is exposed via network interfaces to handle inbound authentication requests, remote attackers can interact directly with the authentication endpoint.\nExecution of the attack requires remote network access to the target instance. The high attack complexity and difficult exploitability characteristics imply that successful exploitation likely demands precise timing, specific environmental conditions, or crafted payload manipulation to bypass the flawed verification checks in apps/web/server/auth.ts.\nThe step-by-step attack flow typically begins with the attacker initiating an OAuth authentication flow against the karakeep instance.\nDue to the improper authentication handling within the server-side logic, the attacker supplies manipulated parameters or intercepts the callback mechanism to deceive the server into granting an authenticated session without possessing valid credentials.\nUpon successful traversal of the flawed authentication checks, the server issues a valid session token or authentication cookie to the attacker.\nPost-exploitation impact includes unauthorized access to user accounts, session hijacking, and potential exposure of sensitive application data managed by the karakeep instance, depending on the privileges associated with the targeted OAuth context."
}
CVE-2026-75774: Karakeep OAuth Sign-In Improper Authentication (LOW Severity, CVSS: 3.7) - Sceawere