Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40349

28
FAUCET Score

OVERVIEW CVE-2026-40349 is a privilege escalation vulnerability in Movary, a self-hosted web application for tracking and rating movies. The flaw allows any authenticated user to elevate their own account to administrator privileges by sending a crafted request with the isAdmin=true parameter to the user settings endpoint. The vulnerability exists in versions prior to 0.71.1 due to insufficient authorization checks on a sensitive administrative field. SEVERITY The vulnerability carries a CVSS score of 8.8 (HIGH) with a network-based attack vector requiring only low complexity and valid user credentials. No user interaction is required for exploitation. The impact is severe, affecting confidentiality, integrity, and availability, as successful exploitation grants full administrative access to the application. This allows threat actors to modify all application data, access sensitive information, and potentially compromise the entire system. EXPLOITATION STATUS The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog, indicating no confirmed active exploitation in the wild at this time. The EPSS score of 0.000130000 reflects minimal probability of exploitation, though this metric should be monitored as public disclosure increases. Community attention appears limited based on the inactive status on public vulnerability tracking lists. However, organizations running Movary versions prior to 0.71.1 should prioritize immediate patching given the straightforward nature of exploitation and the critical nature of privilege escalation vulnerabilities.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.71.1CPE matchmatch criteria
cpe:2.3:a:leepeuker:movary:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.53%
Probability of exploitation in next 30 days
EPSS Percentile
41.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0053 is in the 31st percentile among its peer group of 17,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / leepeuker/movary/commit/12c8a090051b1a1c07a3aa48922f3bc9ffe44c8b
Patch
github.com / leepeuker/movary/pull/750
Issue TrackingPatch
github.com / leepeuker/movary/releases/tag/0.71.1
Release Notes
github.com / leepeuker/movary/security/advisories/GHSA-mcfq-8rx7-w25v
ExploitVendor Advisory