Ad

CVE-2026-32702

MEDIUM CVSS 4.0: 6.9 EPSS 0.08%
Updated Mar 18, 2026
Cleanuparr
Parameter Value
CVSS 6.9 (MEDIUM)
Affected Versions 2.7.0 — 2.8.1
Fixed In 2.8.1
Type CWE-208
Vendor Cleanuparr
Public PoC No

Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download clients like qBittorrent. From 2.7.0 to 2.8.0, the /api/auth/login endpoint contains a logic flaw that allows unauthenticated remote attackers to enumerate valid usernames by measuring the application's response time. It appears that the hashing function, which is the most time-consuming part of the process by design, occurs as part of the VerifyPassword function.

With the short circuits occurring before the hashing function, a timing differential is introduced that exposes validity to the actor. This vulnerability is fixed in 2.8.1.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Cleanuparr_Project Cleanuparr
cpe:2.3:a:cleanuparr_project:cleanuparr:*:*:*:*:*:*:*:*
2.7.0 2.8.1