CVE-2026-45273

8.7

PoxenStudio · Talebook

Talebook (MyBooks) is susceptible to a missing authorization vulnerability that allows authenticated users to perform unauthorized actions.

Executive summary

A missing authorization flaw in Talebook allows authenticated attackers to perform unauthorized operations, potentially leading to full system compromise.

Vulnerability

This vulnerability is a missing authorization flaw (CWE-862) within the Talebook web server. It permits an authenticated user to bypass intended access controls and execute functions they are not authorized to access.

Business impact

Successful exploitation of this vulnerability allows an attacker with low-level privileges to gain unauthorized control over core application functions. Given the CVSS score of 8.7, this is a high-severity issue that could result in total compromise of the application data and integrity. Organizations relying on Talebook for sensitive document management face significant risks of unauthorized data access or modification.

Remediation

Immediate Action: Update Talebook to version 3.42.0 or later immediately to resolve the missing authorization check.

Proactive Monitoring: Review application access logs for unusual patterns of administrative function calls originating from standard user accounts.

Compensating Controls: Implement strict network access controls to limit the exposure of the Talebook interface to trusted internal networks only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The high CVSS score and the presence of a known proof-of-concept necessitate immediate action. Administrators must prioritize updating to version 3.42.0 to eliminate the risk of privilege escalation and unauthorized system control.