OVERVIEW CVE-2026-40349 is a privilege escalation vulnerability in Movary, a self-hosted web application for tracking and rating movies. The flaw allows any authenticated user to elevate their own account to administrator privileges by sending a crafted request with the isAdmin=true parameter to the user settings endpoint. The vulnerability exists in versions prior to 0.71.1 due to insufficient authorization checks on a sensitive administrative field. SEVERITY The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring only low complexity and valid user credentials. No user interaction is required for exploitation. The impact is severe, affecting confidentiality, integrity, and availability, as successful exploitation grants full administrative access to the application. This allows threat actors to modify all application data, access sensitive information, and potentially compromise the entire system. EXPLOITATION STATUS The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, indicating no confirmed active exploitation in the wild at this time. The EPSS score of 0.000130000 reflects minimal probability of exploitation, though this metric should be monitored as public disclosure increases. Community attention appears limited based on the inactive status on public vulnerability tracking lists. However, organizations running Movary versions prior to 0.71.1 should prioritize immediate patching given the straightforward nature of exploitation and the critical nature of privilege escalation vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.71.1CPE matchmatch criteria | cpe:2.3:a:leepeuker:movary:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.