CVE-2026-30975 describes a critical authentication bypass vulnerability in Sonarr versions prior to 4.0.16.2942 (nightly) or 4.0.16.2944 (stable), affecting instances with disabled local address authentication and no robust reverse proxy. This flaw carries a CVSS score of 9.8, indicating it allows unauthenticated remote attackers to achieve complete compromise of confidentiality, integrity, and availability with low attack complexity. While there is no evidence of active exploitation or public exploit code, the vulnerability has received some community discussion. Patches are available in the specified versions, and workarounds include enabling authentication, using a reverse proxy, or accessing Sonarr via a VPN.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.16.2942CPE matchmatch criteria | cpe:2.3:a:sonarr:sonarr:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.