216.73.217.22

CVE-2026-32702

· Published 16/03/2026 14:19 · Modified 16/03/2026 18:16

Labels: CVE-2026-32702 2026-03-16CVE-2026-32702CWE-208[email protected]

Essential information

Published
16/03/2026 14:19
Modified
16/03/2026 18:16
Author
Creator
CVSS
6.9 MEDIUM (v3) 6.9 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. From 2.7.0 to 2.8.0, the /api/auth/login endpoint contains a logic flaw that allows unauthenticated remote attackers to enumerate valid usernames by measuring the application's response time. It appears that the hashing function, which is the most time-consuming part of the process by design, occurs as part of the VerifyPassword function. With the short circuits occurring before the hashing function, a timing differential is introduced that exposes validity to the actor. This vulnerability is fixed in 2.8.1.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
cleanuparr / cleanuparr cpe:2.3:a:cleanuparr:cleanuparr:2.7.0-2.8.0:*:*:*:*:*:*:*
sonarr / sonarr cpe:2.3:a:sonarr:sonarr:*:*:*:*:*:*:*:*
radarr / radarr cpe:2.3:a:radarr:radarr:*:*:*:*:*:*:*:*
qbittorrent / qbittorrent cpe:2.3:a:qbittorrent:qbittorrent:*:*:*:*:*:*:*:*

References