Sonarr disclosed two high-severity vulnerabilities affecting 4.x releases: CVE-2026-30975, an authentication bypass in versions before 4.0.16.2942/4.0.16.2944, and CVE-2026-30976, a path traversal issue in versions before 4.0.17.2950/4.0.17.2952. The authentication bypass can be triggered when Sonarr is configured as "Disabled for Local Addresses" and is exposed without a reverse proxy that blocks or strips the invalid header used in the attack, potentially allowing unauthorized access. The path traversal flaw affects Windows deployments and could let an unauthenticated remote attacker read arbitrary files accessible to the Sonarr process.
The file-read exposure could include Sonarr configuration files containing API keys and database credentials, as well as Windows system files and other user-accessible files on the same drive. Sonarr has released fixes for both issues and advised administrators to upgrade promptly, enable authentication, avoid direct internet exposure, and place the service behind a properly configured reverse proxy or restrict access to an internal network using VPN or Tailscale-style remote access.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-30976 was publicly disclosed as a path traversal vulnerability affecting Sonarr 4.x versions prior to 4.0.17.2950 on Windows. The disclosure noted that exposed instances could allow unauthenticated reading of sensitive files, including configuration data and system files.
GitHub security advisories recorded CVE-2026-30975 on March 25, 2026, classifying it as an authentication bypass issue in Sonarr and assigning CWE-290 and a high-severity CVSS v3.1 score. The advisory documented affected versions prior to 4.0.16.2942 and listed mitigations such as enabling authentication and avoiding direct internet exposure.
Sonarr patched a Windows-only path traversal vulnerability later assigned CVE-2026-30976 in version 4.0.17.2950 for nightly/develop and 4.0.17.2952 for stable/main. The flaw could let an unauthenticated remote attacker read arbitrary files accessible to the Sonarr process.
Sonarr released fixes for an authentication bypass vulnerability later assigned CVE-2026-30975, with patched versions 4.0.16.2942 for the nightly/develop branch and 4.0.16.2944 for stable/main. The issue affected deployments using "Disabled for Local Addresses" authentication and exposed without a protective reverse proxy.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.