VDB
CVE-2026-0616
CVE-2026-0616
PUBLISHED
CVSS 7.5 HIGH
TheLibrarians web_fetch tool can be used to retrieve the Adminer interface content, which can then be used to log into the internal TheLibrarian backend system. The vendor has fixed the vulnerability in all affected versions.
EPSS 0.02% · 4.2th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.02%
4.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| TheLibrarian | TheLibrarian.io | 0, 0 |
| thelibrarian | the_librarian |
Timeline
- Jan 16, 2026 CVE Published
- Jan 16, 2026 PoC Published
- Jan 17, 2026 EPSS Score
- Jan 17, 2026 CVE Updated
- Jan 17, 2026 PoC Published
- Jan 20, 2026 EPSS Score
- Jan 23, 2026 EPSS Score
- Jan 26, 2026 EPSS Score
- Jan 28, 2026 EPSS Score
- Jan 31, 2026 EPSS Score
- Feb 3, 2026 EPSS Score
- Feb 6, 2026 EPSS Score