Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35032

29
FAUCET Score

Jellyfin versions prior to 10.11.7 contain a critical vulnerability chain in the LiveTV M3U tuner endpoint that fails to validate tuner URLs, permitting local file read operations and server-side request forgery attacks. The flaw is particularly dangerous because the EnableLiveTvManagement permission defaults to true for all new users, making it exploitable by any authenticated user without requiring special privileges. An attacker can weaponize this by adding a malicious M3U tuner that exfiltrates the Jellyfin database, extract admin session tokens, and escalate to administrator access. The vulnerability carries a CVSS 3.1 score of 8.1 (HIGH) with a network attack vector, low complexity, and requires only low privileges and user interaction. The attack has high confidentiality and integrity impacts, as attackers can both read sensitive files including database contents and potentially modify system configuration. The EPSS score of 0.0004 indicates minimal current exploitation activity in the wild, though the moderate FAUCET Risk Score of 49.0 suggests notable community concern. This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog, nor is it on the Hot List for active exploitation. No publicly available exploit code has emerged based on available intelligence. Remediation through upgrade to version 10.11.7 is strongly recommended, with the alternative mitigation of disabling Live TV Management privileges for all users available for organizations unable to patch immediately.

Impacted Technologies

VendorProductVersion(s)CPE
< 10.11.7CPE matchmatch criteria
cpe:2.3:a:jellyfin:jellyfin:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.6HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
LOW
SS Integrity
LOW
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.31%
Probability of exploitation in next 30 days
EPSS Percentile
23.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0031 is in the 11th percentile among its peer group of 17,844 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryworkaround availablevia nvd_reference
View patch

References

github.com / jellyfin/jellyfin/releases/tag/v10.11.7
ProductRelease Notes
github.com / jellyfin/jellyfin/security/advisories/GHSA-8fw7-f233-ffr8
ExploitMitigationVendor Advisory