CVE-2026-30975 Details
Description
Sonarr is a PVR for Usenet and BitTorrent users. Versions prior to 4.0.16.2942 have an authentication bypass that affected users that had disabled authentication for local addresses (Authentication Required set to: `Disabled for Local Addresses`) without a reverse proxy running in front of Sonarr that didn't not pass through the invalid header. Patches are available in version 4.0.16.2942 in the nightly/develop branch and version 4.0.16.2944 for stable/main releases. Some workarounds are available. Make sure Sonarr's Authentication Required setting is set to `Enabled`, run Sonarr behind a reverse proxy, and/or do not expose Sonarr directly to the internet and instead rely on accessing it through a VPN, Tailscale or a similar solution.
A vulnerability in Sonarr versions prior to 4.0.16.2942 allows authentication bypass for users who disabled authentication for local addresses. This issue arises when Sonarr is not behind a properly configured reverse proxy that handles the X-Forwarded-For header, leaving the application exposed to unauthorized access.
Users can upgrade to Sonarr version 4.0.16.2942 in the nightly/develop branch or version 4.0.16.2944 for stable/main releases. Additionally, ensure that Sonarr's Authentication Required setting is enabled, run Sonarr behind a reverse proxy configured for X-Forwarded-For header handling, and avoid exposing Sonarr directly to the internet. Instead, access it through a VPN, Tailscale, or a similar solution.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Sonarr/Sonarr/releases/tag/v4.0.16.2942 | [email protected] | Release Notes |
| https://github.com/Sonarr/Sonarr/releases/tag/v4.0.16.2944 | [email protected] | Release Notes |
| https://github.com/Sonarr/Sonarr/security/advisories/GHSA-h5qx-5hjf-7c9r | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sonarr sonarr | < 4.0.16.2942 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 30, 2026 | Initial Analysis | [email protected] |
| Mar 25, 2026 | New CVE Received | [email protected] |