SB2026092330 - Authorization bypass through user-controlled key in Jellyfin



SB2026092330 - Authorization bypass through user-controlled key in Jellyfin

Published: September 23, 2026

Security Bulletin ID SB2026092330
CSH Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Authorization bypass through user-controlled key (CVE-ID: N/A)

CWE-ID: CWE-639 - Authorization Bypass Through User-Controlled Key

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to broken access control in session remote-control API. A remote user can provide the target session ID to control another user's session, send popups, control playback and execute system commands.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.