Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

calibre e-book manager writes unauthorized files to disk

CVE-2026-26065
Summary

Versions 9.2.1 and below of calibre allow attackers to write unauthorized files to your computer, potentially leading to data corruption or code execution. This issue has been fixed in version 9.3.0, so update to that version or later to protect your system. If you can't update, ensure calibre is run with limited user permissions to minimize potential damage.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
calibre-ebook calibre <= 9.3.0 –
Original title
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-byte and...
Original description
calibre is a cross-platform e-book manager for viewing, converting, editing, and cataloging e-books. Versions 9.2.1 and below are vulnerable to Path Traversal through PDB readers (both 132-byte and 202-byte header variants) that allow arbitrary file writes with arbitrary extension and arbitrary content anywhere the user has write permissions. Files are written in 'wb' mode, silently overwriting existing files. This can lead to potential code execution and Denial of Service through file corruption. This issue has been fixed in version 9.3.0.
nvd CVSS3.1 8.8
nvd CVSS4.0 9.3
Vulnerability type
CWE-22 Path Traversal
Published: 20 Feb 2026 · Updated: 11 Mar 2026 · First seen: 6 Mar 2026