OVERVIEW CVE-2026-40348 affects Movary, a self-hosted web application for tracking and rating movies. Prior to version 0.71.1, the application contains a Server-Side Request Forgery (SSRF) vulnerability in the Jellyfin server URL verification endpoint that permits authenticated users to trigger arbitrary internal network requests. SEVERITY The vulnerability carries a CVSS score of 7.7 (HIGH) with a network-based attack vector requiring only low complexity and valid user authentication. The impact is significant, providing attackers with high confidentiality compromise potential through internal network reconnaissance capabilities. The flaw enables attackers to probe internal hosts and ports, fingerprint services, and potentially access administrative interfaces or cloud metadata endpoints not exposed externally. The scope is changed, meaning the vulnerability can affect resources beyond the vulnerable application itself. EXPLOITATION STATUS There is no evidence of active exploitation in the wild, with an EPSS score of 0.00009 indicating this vulnerability ranks lower than 99.99 percent of known CVEs in terms of exploitation probability. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog, and community attention remains minimal. However, the exploitation mechanics are straightforward for authenticated users with basic HTTP knowledge, and Movary administrators should prioritize upgrading to version 0.71.1 to eliminate this internal reconnaissance risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.71.1CPE matchmatch criteria | cpe:2.3:a:leepeuker:movary:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.