#1144839 sabnzbdplus: authentication bypass in the web interface

Package:
src:sabnzbdplus
Source:
src:sabnzbdplus
Submitter:
Jeroen Ploemen
Date:
2026-08-20 08:39:02 UTC
Severity:
normal
Tags:
#1144839#5
Date:
2026-08-19 10:18:30 UTC
From:
To:
Hi,

a vulnerability was discovered in sabnzbdplus that allows any client
with access to the password-protected web interface to obtain an
authenticated session without knowing the username or password.

Affected versions are all since 3.0.0 through 5.1.0; for Debian that
translates to every release since bullseye. Fixed in upstream release
5.1.1, meanwhile uploaded to unstable as 5.1.1+dfsg-1.

CVE: [not yet]
Github: https://github.com/sabnzbd/sabnzbd/security/advisories/GHSA-xrfq-jhgh-wqch
Fix: https://github.com/sabnzbd/sabnzbd/commit/9a12300877a38becda23dada37fd4f9c488801a5

Patches (source debdiff) for the sabnzbdplus package in bookworm and
trixie are attached, and published in the {bookworm,trixie}-security
branches in the package's VCS on salsa. Both have been verified to
build, install, run, and fix the security issue.

#1144839#10
Date:
2026-08-20 08:37:11 UTC
From:
To:
also attaching a debdiff for bullseye, although I realise the long
term support phase for that release is about to end soon.