Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-45274— MyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER Enforcement

Quick assessment

Affected
PoxenStudio talebook
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MyBooks(也被称为 Talebook)是一个电子书管理 Web 服务器。在版本 3.41.2 及更早版本中, 文件中的 处理器在处理 请求时,未强制执行 配置标志。尽管前端在 标志为 时会隐藏注册控件,但该后端端点仍允许调用。未认证的远程攻击者可以直接调用该端点,在管理员已禁用公开注册的功能的实例上创建有效账户。 此外, 中的 函数也未验证账户的“激活状态”标志,因此新创建且尚未激活的账户可以立即进行身份验证,并访问用户级别的 API 功能。 此漏洞绕过了预期的账户创建策略,攻击者可借此获取低权限账户,从而触

CVSS 6.9 · Medium EPSS 0.52% · P42

Affected Version Matrix 1

VendorProduct Version RangeStatus
PoxenStudio talebook < 3.42.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-45274

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER Enforcement
Source: CVE Program / CVE List V5
Vulnerability Description
MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST /api/user/sign_up in webserver/handlers/user.py does not enforce the ALLOW_REGISTER configuration flag, even though the frontend hides registration controls when the flag is false. An unauthenticated remote attacker can call the endpoint directly and create a valid account on an instance whose administrator disabled public registration. The process_auth_header function in webserver/handlers/base.py also does not verify the account's active flag, so the newly created and unactivated account can authenticate immediately and access user-level API functionality. The bypass defeats the intended account-creation policy and can supply the low-privilege account required by related authorization vulnerabilities. This issue is fixed in version 3.42.0.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
服务端安全的客户端实施
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
PoxenStudio talebook < 3.42.0 -

II. Public POCs for CVE-2026-45274

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-45274

登录查看更多情报信息。

Patches & Fixes for CVE-2026-45274 (2)

Vendor Advisories for CVE-2026-45274 (1)

Same Patch Batch · PoxenStudio · 2026-08-19 · 3 CVEs total

CVE-2026-45272 9.4 CRITICAL MyBooks: Remote Code Execution via SOCIAL_AUTH Key Name Injection in Python Config File
CVE-2026-45273 8.7 HIGH MyBooks: Privilege Escalation via Missing Authorization on Admin Settings Endpoint

IV. Related Vulnerabilities

V. Comments for CVE-2026-45274

No comments yet


Leave a comment