CVE-2026-90941EPSS p32.6%
CVE-2026-90941CVE-2026-90941
Description
novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookId and bookName to retrieve all chapter content without VIP or purchase verification, bypassing the permission checks and data-scope limits enforced elsewhere in the admin interface.
Scoring
| CVSS | 4.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 0.41% probability of exploitation · percentile 32.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-23 |