Authorization bypass through user-controlled key in Jellyfin - #VU151795

 

Authorization bypass through user-controlled key in Jellyfin - #VU151795

Published: September 23, 2026


Vulnerability identifier: #VU151795
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to broken access control in session remote-control API. A remote user can provide the target session ID to control another user's session, send popups, control playback and execute system commands.


Affected software

Jellyfin

Remediation

Install updates from vendor's website.


External References