Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35031

33
FAUCET Score

Jellyfin versions prior to 10.11.7 contain a critical vulnerability in the subtitle upload endpoint that allows authenticated users with administrator privileges or explicit subtitle upload permissions to perform arbitrary file writes through insufficient validation of the Format field. This vulnerability can be exploited to achieve remote code execution with root privileges by chaining the file write capability into arbitrary file read operations, database extraction, and privilege escalation through ld.so.preload manipulation. The vulnerability has a CVSS score of 9.9 (Critical) with a network attack vector, low complexity, and requirements for low privilege access. The exploit chain results in complete compromise of confidentiality, integrity, and availability across the affected system. The EPSS score of 0.002840000 indicates relatively low prevalence among known vulnerabilities, though the high CVSS score reflects significant potential impact. There is no evidence of active exploitation in the wild, and the vulnerability does not appear on CISA's Known Exploited Vulnerabilities list. The patch is available in version 10.11.7 and was released following responsible disclosure. Organizations unable to immediately upgrade should consider restricting subtitle upload permissions to administrative accounts only to minimize attack surface.

Impacted Technologies

VendorProductVersion(s)CPE
< 10.11.7CPE matchmatch criteria
cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.9CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.1
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.75%
Probability of exploitation in next 30 days
EPSS Percentile
51.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0075 is in the 44th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryworkaround availablevia nvd_reference
View patch

References

github.com / jellyfin/jellyfin/releases/tag/v10.11.7
ProductRelease Notes
github.com / jellyfin/jellyfin/security/advisories/GHSA-j2hf-x4q5-47j3
MitigationVendor Advisory