Sceawere
Vulnerability Detail
CVE-2026-93954UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Grimmory Settings API Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- grimmory-tools
- Product
- grimmory
- Attack Type
- Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSettingController.getAppSettings of the file backend/src/main/java/org/booklore/controller/AppSettingController.java of the component Settings API Endpoint. Such manipulation leads to incorrect authorization. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The name of the patch is 2b66ca6df8110f6b512e030b54c16b9fbe318f17. Applying a patch is advised to resolve this issue. PR #2558, merged as 53abc8b, moved the OIDC secret into a dedicated setting, but did not by itself restrict GET /api/v1/settings.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-19T22:16:28.453Z",
"pubdate": "2026-09-19T22:16:28.453Z",
"executiveSummary": "A critical authorization vulnerability has been identified in the Grimmory Settings API, specifically within the AppSettingController.getAppSettings function. The vulnerability allows unauthorized remote actors to access sensitive application settings due to insufficient access control mechanisms. This flaw affects Grimmory versions up to 3.3.3 and 3.4.1. The security risk is significant as it potentially exposes configuration data, including OIDC secrets, which could lead to further system compromise or unauthorized administrative access. The vulnerability is publicly disclosed, necessitating immediate attention. While PR #2558 (commit 53abc8b) addressed the exposure of the OIDC secret by moving it to a dedicated setting, it failed to implement the necessary access control restrictions on the underlying GET /api/v1/settings endpoint, leaving the root authorization flaw unmitigated until the application of patch 2b66ca6df8110f6b512e030b54c16b9fbe318f17.",
"technicalDetails": "The vulnerability resides in the backend/src/main/java/org/booklore/controller/AppSettingController.java file within the Grimmory Settings API component. The core issue stems from an incorrect authorization check within the AppSettingController.getAppSettings function. This function is responsible for retrieving application configuration settings, which may contain sensitive security parameters, including OpenID Connect (OIDC) secrets and other configuration metadata.\nAnalysis indicates that the application fails to enforce appropriate authentication or role-based access control (RBAC) constraints when handling GET requests to the /api/v1/settings endpoint. Consequently, any remote attacker can invoke this endpoint to retrieve the full set of application settings without providing valid credentials or possessing administrative privileges. The vulnerability exists because the controller logic implicitly assumes that the request context or the nature of the data does not require strict authorization enforcement, or it relies on an insecure default configuration.\nThe attack flow involves a remote actor sending a standard HTTP GET request to the /api/v1/settings endpoint. Upon receipt, the AppSettingController.getAppSettings method executes, serializes the application configuration settings, and returns the response directly to the requester. Because the authorization logic is either absent or improperly implemented, the application does not validate the identity of the user or the session state prior to disclosure.\nThe post-exploitation impact is severe. An attacker obtaining these configuration parameters can gain unauthorized visibility into the infrastructure's authentication flow, service integrations, and underlying logic. In environments where OIDC secrets or similar cryptographic material are stored within the settings object, the attacker may be able to manipulate authentication tokens or impersonate legitimate services, leading to a complete compromise of the integration security model. Although PR #2558 attempted to isolate the OIDC secret from generic settings, the fundamental architectural flaw remains that the entire configuration object is exposed to unauthorized callers. The official patch, 2b66ca6df8110f6b512e030b54c16b9fbe318f17, is required to rectify the authorization bypass by enforcing granular access controls at the controller level."
}