{"id":"CVE-2026-51876","title":"DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow","summary":"DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a publicly exposed book_id to submit a confirm-proposal request for an existing book, causi…","severity":"none","published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T22:17:02.387","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-51876","references":[{"url":"https://gist.github.com/Ro1ME/c5685936179edcbf942f3fdd745d1473","label":"cve@mitre.org"},{"url":"https://github.com/HKUDS/DeepTutor/issues/514","label":"cve@mitre.org"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-01T23:03:32.773Z","slug":"CVE-2026-51876","body":"## Overview\n\nDeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a publicly exposed book_id to submit a confirm-proposal request for an existing book, causing unauthorized overwrites of persisted metadata and spine content.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}