Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-30976

Sonarr is a PVR for Usenet and BitTorrent users. In versions on the 4.x branch prior to 4.0.17.2950, an unauthenticated remote attacker can potentially read any file readable by the Sonarr process. These include application configuration files (containing API keys and database credentials), Windows system files, and any user-accessible files on the same drive This issue only impacts Windows systems; macOS and Linux are unaffected. Files returned from the API were not limited to the directory on disk they were intended to be served from. This problem has been patched in 4.0.17.2950 in the nightly/develop branch or 4.0.17.2952 for stable/main releases. It's possible to work around the issue by only hosting Sonarr on a secure internal network and accessing it via VPN, Tailscale or similar solution outside that network.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 6.0%
CVSS Severity
CVSS v3 Score 8.6
Products affected by CVE-2026-30976
  • Sonarr » Sonarr » Version: 4.0.0.741
    cpe:2.3:a:sonarr:sonarr:4.0.0.741
  • Sonarr » Sonarr » Version: 4.0.0.748
    cpe:2.3:a:sonarr:sonarr:4.0.0.748
  • Sonarr » Sonarr » Version: 4.0.0.825
    cpe:2.3:a:sonarr:sonarr:4.0.0.825
  • Sonarr » Sonarr » Version: 4.0.0.836
    cpe:2.3:a:sonarr:sonarr:4.0.0.836
  • Sonarr » Sonarr » Version: 4.0.0.924
    cpe:2.3:a:sonarr:sonarr:4.0.0.924
  • Sonarr » Sonarr » Version: 4.0.1.1014
    cpe:2.3:a:sonarr:sonarr:4.0.1.1014
  • Sonarr » Sonarr » Version: 4.0.1.1047
    cpe:2.3:a:sonarr:sonarr:4.0.1.1047
  • Sonarr » Sonarr » Version: 4.0.1.1096
    cpe:2.3:a:sonarr:sonarr:4.0.1.1096
  • Sonarr » Sonarr » Version: 4.0.1.1114
    cpe:2.3:a:sonarr:sonarr:4.0.1.1114
  • Sonarr » Sonarr » Version: 4.0.1.1131
    cpe:2.3:a:sonarr:sonarr:4.0.1.1131
  • Sonarr » Sonarr » Version: 4.0.1.1168
    cpe:2.3:a:sonarr:sonarr:4.0.1.1168
  • Sonarr » Sonarr » Version: 4.0.1.929
    cpe:2.3:a:sonarr:sonarr:4.0.1.929
  • Sonarr » Sonarr » Version: 4.0.1.933
    cpe:2.3:a:sonarr:sonarr:4.0.1.933
  • Sonarr » Sonarr » Version: 4.0.1.947
    cpe:2.3:a:sonarr:sonarr:4.0.1.947
  • Sonarr » Sonarr » Version: 4.0.1.953
    cpe:2.3:a:sonarr:sonarr:4.0.1.953
  • Sonarr » Sonarr » Version: 4.0.1.987
    cpe:2.3:a:sonarr:sonarr:4.0.1.987
  • Sonarr » Sonarr » Version: 4.0.10.2544
    cpe:2.3:a:sonarr:sonarr:4.0.10.2544
  • Sonarr » Sonarr » Version: 4.0.10.2579
    cpe:2.3:a:sonarr:sonarr:4.0.10.2579
  • Sonarr » Sonarr » Version: 4.0.10.2624
    cpe:2.3:a:sonarr:sonarr:4.0.10.2624
  • Sonarr » Sonarr » Version: 4.0.10.2656
    cpe:2.3:a:sonarr:sonarr:4.0.10.2656
  • Sonarr » Sonarr » Version: 4.0.11.2680
    cpe:2.3:a:sonarr:sonarr:4.0.11.2680
  • Sonarr » Sonarr » Version: 4.0.11.2688
    cpe:2.3:a:sonarr:sonarr:4.0.11.2688
  • Sonarr » Sonarr » Version: 4.0.11.2697
    cpe:2.3:a:sonarr:sonarr:4.0.11.2697
  • Sonarr » Sonarr » Version: 4.0.11.2724
    cpe:2.3:a:sonarr:sonarr:4.0.11.2724
  • Sonarr » Sonarr » Version: 4.0.11.2743
    cpe:2.3:a:sonarr:sonarr:4.0.11.2743
  • Sonarr » Sonarr » Version: 4.0.11.2762
    cpe:2.3:a:sonarr:sonarr:4.0.11.2762
  • Sonarr » Sonarr » Version: 4.0.11.2774
    cpe:2.3:a:sonarr:sonarr:4.0.11.2774
  • Sonarr » Sonarr » Version: 4.0.11.2784
    cpe:2.3:a:sonarr:sonarr:4.0.11.2784
  • Sonarr » Sonarr » Version: 4.0.11.2793
    cpe:2.3:a:sonarr:sonarr:4.0.11.2793
  • Sonarr » Sonarr » Version: 4.0.11.2800
    cpe:2.3:a:sonarr:sonarr:4.0.11.2800
  • Sonarr » Sonarr » Version: 4.0.11.2804
    cpe:2.3:a:sonarr:sonarr:4.0.11.2804
  • Sonarr » Sonarr » Version: 4.0.11.2815
    cpe:2.3:a:sonarr:sonarr:4.0.11.2815
  • Sonarr » Sonarr » Version: 4.0.12.2823
    cpe:2.3:a:sonarr:sonarr:4.0.12.2823
  • Sonarr » Sonarr » Version: 4.0.12.2825
    cpe:2.3:a:sonarr:sonarr:4.0.12.2825
  • Sonarr » Sonarr » Version: 4.0.12.2849
    cpe:2.3:a:sonarr:sonarr:4.0.12.2849
  • Sonarr » Sonarr » Version: 4.0.12.2866
    cpe:2.3:a:sonarr:sonarr:4.0.12.2866
  • Sonarr » Sonarr » Version: 4.0.12.2892
    cpe:2.3:a:sonarr:sonarr:4.0.12.2892
  • Sonarr » Sonarr » Version: 4.0.12.2900
    cpe:2.3:a:sonarr:sonarr:4.0.12.2900
  • Sonarr » Sonarr » Version: 4.0.13.2931
    cpe:2.3:a:sonarr:sonarr:4.0.13.2931
  • Sonarr » Sonarr » Version: 4.0.13.2932
    cpe:2.3:a:sonarr:sonarr:4.0.13.2932
  • Sonarr » Sonarr » Version: 4.0.13.2933
    cpe:2.3:a:sonarr:sonarr:4.0.13.2933
  • Sonarr » Sonarr » Version: 4.0.13.2934
    cpe:2.3:a:sonarr:sonarr:4.0.13.2934
  • Sonarr » Sonarr » Version: 4.0.14.2938
    cpe:2.3:a:sonarr:sonarr:4.0.14.2938
  • Sonarr » Sonarr » Version: 4.0.14.2939
    cpe:2.3:a:sonarr:sonarr:4.0.14.2939
  • Sonarr » Sonarr » Version: 4.0.15.2940
    cpe:2.3:a:sonarr:sonarr:4.0.15.2940
  • Sonarr » Sonarr » Version: 4.0.15.2941
    cpe:2.3:a:sonarr:sonarr:4.0.15.2941
  • Sonarr » Sonarr » Version: 4.0.16.2942
    cpe:2.3:a:sonarr:sonarr:4.0.16.2942
  • Sonarr » Sonarr » Version: 4.0.16.2943
    cpe:2.3:a:sonarr:sonarr:4.0.16.2943
  • Sonarr » Sonarr » Version: 4.0.16.2944
    cpe:2.3:a:sonarr:sonarr:4.0.16.2944
  • Sonarr » Sonarr » Version: 4.0.16.2946
    cpe:2.3:a:sonarr:sonarr:4.0.16.2946
  • Sonarr » Sonarr » Version: 4.0.2.1183
    cpe:2.3:a:sonarr:sonarr:4.0.2.1183
  • Sonarr » Sonarr » Version: 4.0.2.1192
    cpe:2.3:a:sonarr:sonarr:4.0.2.1192
  • Sonarr » Sonarr » Version: 4.0.2.1223
    cpe:2.3:a:sonarr:sonarr:4.0.2.1223
  • Sonarr » Sonarr » Version: 4.0.2.1262
    cpe:2.3:a:sonarr:sonarr:4.0.2.1262
  • Sonarr » Sonarr » Version: 4.0.2.1312
    cpe:2.3:a:sonarr:sonarr:4.0.2.1312
  • Sonarr » Sonarr » Version: 4.0.2.1341
    cpe:2.3:a:sonarr:sonarr:4.0.2.1341
  • Sonarr » Sonarr » Version: 4.0.2.1367
    cpe:2.3:a:sonarr:sonarr:4.0.2.1367
  • Sonarr » Sonarr » Version: 4.0.2.1408
    cpe:2.3:a:sonarr:sonarr:4.0.2.1408
  • Sonarr » Sonarr » Version: 4.0.3.1413
    cpe:2.3:a:sonarr:sonarr:4.0.3.1413
  • Sonarr » Sonarr » Version: 4.0.3.1442
    cpe:2.3:a:sonarr:sonarr:4.0.3.1442
  • Sonarr » Sonarr » Version: 4.0.3.1465
    cpe:2.3:a:sonarr:sonarr:4.0.3.1465
  • Sonarr » Sonarr » Version: 4.0.3.1486
    cpe:2.3:a:sonarr:sonarr:4.0.3.1486
  • Sonarr » Sonarr » Version: 4.0.4.1491
    cpe:2.3:a:sonarr:sonarr:4.0.4.1491
  • Sonarr » Sonarr » Version: 4.0.4.1515
    cpe:2.3:a:sonarr:sonarr:4.0.4.1515
  • Sonarr » Sonarr » Version: 4.0.4.1572
    cpe:2.3:a:sonarr:sonarr:4.0.4.1572
  • Sonarr » Sonarr » Version: 4.0.4.1616
    cpe:2.3:a:sonarr:sonarr:4.0.4.1616
  • Sonarr » Sonarr » Version: 4.0.4.1650
    cpe:2.3:a:sonarr:sonarr:4.0.4.1650
  • Sonarr » Sonarr » Version: 4.0.4.1668
    cpe:2.3:a:sonarr:sonarr:4.0.4.1668
  • Sonarr » Sonarr » Version: 4.0.4.1692
    cpe:2.3:a:sonarr:sonarr:4.0.4.1692
  • Sonarr » Sonarr » Version: 4.0.4.1695
    cpe:2.3:a:sonarr:sonarr:4.0.4.1695
  • Sonarr » Sonarr » Version: 4.0.4.1699
    cpe:2.3:a:sonarr:sonarr:4.0.4.1699
  • Sonarr » Sonarr » Version: 4.0.5.1710
    cpe:2.3:a:sonarr:sonarr:4.0.5.1710
  • Sonarr » Sonarr » Version: 4.0.5.1719
    cpe:2.3:a:sonarr:sonarr:4.0.5.1719
  • Sonarr » Sonarr » Version: 4.0.5.1740
    cpe:2.3:a:sonarr:sonarr:4.0.5.1740
  • Sonarr » Sonarr » Version: 4.0.5.1760
    cpe:2.3:a:sonarr:sonarr:4.0.5.1760
  • Sonarr » Sonarr » Version: 4.0.5.1778
    cpe:2.3:a:sonarr:sonarr:4.0.5.1778
  • Sonarr » Sonarr » Version: 4.0.5.1782
    cpe:2.3:a:sonarr:sonarr:4.0.5.1782
  • Sonarr » Sonarr » Version: 4.0.5.1791
    cpe:2.3:a:sonarr:sonarr:4.0.5.1791
  • Sonarr » Sonarr » Version: 4.0.5.1801
    cpe:2.3:a:sonarr:sonarr:4.0.5.1801
  • Sonarr » Sonarr » Version: 4.0.6.1805
    cpe:2.3:a:sonarr:sonarr:4.0.6.1805
  • Sonarr » Sonarr » Version: 4.0.6.1820
    cpe:2.3:a:sonarr:sonarr:4.0.6.1820
  • Sonarr » Sonarr » Version: 4.0.6.1847
    cpe:2.3:a:sonarr:sonarr:4.0.6.1847
  • Sonarr » Sonarr » Version: 4.0.7.1863
    cpe:2.3:a:sonarr:sonarr:4.0.7.1863
  • Sonarr » Sonarr » Version: 4.0.7.1868
    cpe:2.3:a:sonarr:sonarr:4.0.7.1868
  • Sonarr » Sonarr » Version: 4.0.8.1874
    cpe:2.3:a:sonarr:sonarr:4.0.8.1874
  • Sonarr » Sonarr » Version: 4.0.8.1893
    cpe:2.3:a:sonarr:sonarr:4.0.8.1893
  • Sonarr » Sonarr » Version: 4.0.8.1902
    cpe:2.3:a:sonarr:sonarr:4.0.8.1902
  • Sonarr » Sonarr » Version: 4.0.8.1929
    cpe:2.3:a:sonarr:sonarr:4.0.8.1929
  • Sonarr » Sonarr » Version: 4.0.8.1967
    cpe:2.3:a:sonarr:sonarr:4.0.8.1967
  • Sonarr » Sonarr » Version: 4.0.8.1988
    cpe:2.3:a:sonarr:sonarr:4.0.8.1988
  • Sonarr » Sonarr » Version: 4.0.8.2008
    cpe:2.3:a:sonarr:sonarr:4.0.8.2008
  • Sonarr » Sonarr » Version: 4.0.8.2093
    cpe:2.3:a:sonarr:sonarr:4.0.8.2093
  • Sonarr » Sonarr » Version: 4.0.8.2158
    cpe:2.3:a:sonarr:sonarr:4.0.8.2158
  • Sonarr » Sonarr » Version: 4.0.8.2208
    cpe:2.3:a:sonarr:sonarr:4.0.8.2208
  • Sonarr » Sonarr » Version: 4.0.8.2223
    cpe:2.3:a:sonarr:sonarr:4.0.8.2223
  • Sonarr » Sonarr » Version: 4.0.9.2244
    cpe:2.3:a:sonarr:sonarr:4.0.9.2244
  • Sonarr » Sonarr » Version: 4.0.9.2257
    cpe:2.3:a:sonarr:sonarr:4.0.9.2257
  • Sonarr » Sonarr » Version: 4.0.9.2278
    cpe:2.3:a:sonarr:sonarr:4.0.9.2278
  • Sonarr » Sonarr » Version: 4.0.9.2300
    cpe:2.3:a:sonarr:sonarr:4.0.9.2300
  • Sonarr » Sonarr » Version: 4.0.9.2332
    cpe:2.3:a:sonarr:sonarr:4.0.9.2332
  • Sonarr » Sonarr » Version: 4.0.9.2342
    cpe:2.3:a:sonarr:sonarr:4.0.9.2342
  • Sonarr » Sonarr » Version: 4.0.9.2386
    cpe:2.3:a:sonarr:sonarr:4.0.9.2386
  • Sonarr » Sonarr » Version: 4.0.9.2421
    cpe:2.3:a:sonarr:sonarr:4.0.9.2421
  • Sonarr » Sonarr » Version: 4.0.9.2457
    cpe:2.3:a:sonarr:sonarr:4.0.9.2457
  • Sonarr » Sonarr » Version: 4.0.9.2513
    cpe:2.3:a:sonarr:sonarr:4.0.9.2513


Contact Us

Shodan ® - All rights reserved