id: PYSEC-2026-1229 published: "2026-07-07T14:34:44.645886Z" modified: "2026-07-07T17:23:52.662352Z" aliases: - CVE-2021-3987 - GHSA-fj5v-w2jp-wqvj summary: Improper Access Control in janeczku/calibre-web details: An improper access control vulnerability exists in janeczku/calibre-web. The affected version allows users without public shelf permissions to create public shelves. The vulnerability is due to the `create_shelf` method in `shelf.py` not verifying if the user has the necessary permissions to create a public shelf. This issue can lead to unauthorized actions being performed by users. affected: - package: name: calibreweb ecosystem: PyPI purl: pkg:pypi/calibreweb ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 0.6.15 versions: - 0.6.12 - 0.6.13 - 0.6.14 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2021-3987 - type: WEB url: https://github.com/janeczku/calibre-web/commit/bcdc97641447965af486964537f3821f47b28874 - type: PACKAGE url: https://github.com/janeczku/calibre-web - type: WEB url: https://huntr.com/bounties/29fcc091-87b6-43bc-ab4b-3c0bec3f71df - type: PACKAGE url: https://pypi.org/project/calibreweb - type: ADVISORY url: https://github.com/advisories/GHSA-fj5v-w2jp-wqvj severity: - type: CVSS_V3 score: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N