CVE-2026-58466 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-58466 requires immediate attention.
· 6 min read
Executive Summary
CVE-2026-58466 is a critical authentication bypass in AutoBangumi before 3.2.8. The application seeds a publicly known default administrator account when the users table is empty via add_default_user(). An unauthenticated attacker can log in with those default credentials and take over the app, including RSS feed settings, downloader configuration, and every authenticated API endpoint.
This is CVSS 9.8. It is not currently listed in KEV and there are no confirmed wild exploits, but the impact is full administrative compromise. For solo developers and small teams, treat this as an emergency patch-and-check issue.
Immediate Action
- Upgrade immediately to AutoBangumi 3.2.8 or later. If you cannot patch right away, isolate the service from the internet and restrict access to trusted IPs/VPN only.
- Assume admin credentials may be known. Rotate any passwords, API tokens, downloader credentials, RSS secrets, and webhook keys tied to AutoBangumi.
- Check for unauthorized changes to RSS sources, download clients, notification hooks, and user accounts. Review logs for unexpected logins to the authentication endpoint.
- If you must roll back, do not restore a database snapshot that still contains the seeded default admin account unless you first remove or replace it.
- Review vendor guidance and release notes for 3.2.8+: Vendor advisory / release notes.
Affected Versions
AutoBangumi < 3.2.8vulnerableAutoBangumi 3.2.8+safe, assuming no local reintroduction of default credentials or custom startup seedingAny deployment that starts with an empty users tableis especially at risk because the default admin is created automatically
Resolution Guide
Primary fix: upgrade the application image/package to 3.2.8 or newer. If you deploy from source, update the dependency or release tag used to build the service.
# Docker: pull and redeploy a fixed image tag
docker pull TODO_AUTOBANGUMI_IMAGE:3.2.8
docker stop autobangumi
docker rm autobangumi
docker run -d --name autobangumi TODO_AUTOBANGUMI_IMAGE:3.2.8
# Docker Compose
docker compose pull
docker compose up -d
# npm / yarn / pnpm (if packaged that way)
npm install autobangumi@3.2.8
yarn add autobangumi@3.2.8
pnpm add autobangumi@3.2.8
# Python (if applicable)
pip install --upgrade autobangumi==3.2.8
pipx upgrade autobangumi
# Java (if applicable)
# Maven
mvn versions:use-latest-releases -Dincludes=TODO_GROUP_ID:TODO_ARTIFACT_ID
# Gradle
./gradlew dependencyUpdates
# Linux package managers (if a distro package exists)
sudo apt update
sudo apt install --only-upgrade autobangumi
sudo yum update autobangumi
Hardening while you patch:
# Restrict access at the reverse proxy or firewall
# Example: allow only your VPN or admin subnet
# Nginx example
location / {
allow 10.0.0.0/24;
deny all;
proxy_pass http://127.0.0.1:PORT;
}
Configuration guidance: If your deployment supports feature flags or startup options, disable any automatic user bootstrap / default admin seeding. If no such flag exists, patching is the only safe fix. Avoid exposing the login endpoint publicly until the upgrade is complete.
Code fix example for maintainers: remove hard-coded default credentials and require explicit admin setup on first run.
// BAD: seeds a known admin when users table is empty
// add_default_user()
// GOOD: require manual initialization
if (usersTableIsEmpty()) {
throw new Error("Initial admin setup required. Create credentials via secure setup flow.");
}
Detection & Verification
Check whether you are vulnerable:
# Check app version
autobangumi --version
docker inspect --format '{{.Config.Image}}' autobangumi
# Search for the vulnerable bootstrap function in source or image build artifacts
grep -R "add_default_user" -n .
# Look for default credential seeding or empty-table bootstrap logic
grep -R "default user\|seed.*admin\|users table is empty" -n .
# If you use dependency scanners
npm audit
pip-audit
mvn -q dependency:tree
./gradlew dependencies
Verify the fix:
# Confirm the running version is 3.2.8 or later
autobangumi --version
# Confirm the startup logs no longer mention default user creation
docker logs autobangumi | grep -i "default user\|seed\|admin"
# Confirm the login endpoint rejects the old default credentials
curl -i -X POST https://YOUR-HOST/login \
-H 'Content-Type: application/json' \
-d '{"username":"TODO_DEFAULT_USERNAME","password":"TODO_DEFAULT_PASSWORD"}'
If you have database access, verify that no seeded admin account remains and that the first-run setup flow requires a unique password before the service is exposed.
Risk and Impact
Successful exploitation gives an attacker full administrative access without valid credentials. That means they can alter RSS feed sources, change downloader targets, steal or redirect content, and use authenticated API endpoints to modify the entire application state.
For small teams, the blast radius can include private media libraries, downloader credentials, internal network access through connected services, and persistent compromise if the attacker changes settings or creates new accounts before you notice.