top of page
perceptive_background_267k.jpg

Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any…

Published:

24 maart 2026 om 23:00:00

Alert date:

25 maart 2026 om 22:02:27

Source:

nvd.nist.gov

Click to open the original link from this advisory

Operating Systems, Enterprise Applications

Sonarr PVR application versions on 4.x branch prior to 4.0.17.2950 contain a critical vulnerability allowing unauthenticated remote attackers to read arbitrary files on Windows systems. The vulnerability affects application configuration files containing API keys and database credentials, Windows system files, and user-accessible files. The issue stems from insufficient directory traversal protection in the API. Only Windows systems are affected, with macOS and Linux unaffected. Patches are available in versions 4.0.17.2950 for nightly/develop branch and 4.0.17.2952 for stable/main releases. Workarounds include restricting Sonarr to secure internal networks with VPN access.

Technical details

Mitigation steps:

Affected products:

Sonarr

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page