Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41457

25
FAUCET Score

OwnTone Server versions 28.4 through 29.0 contain a SQL injection vulnerability in DAAP query and filter handling that allows attackers to inject arbitrary SQL expressions through the query= and filter= parameters. The vulnerability stems from insufficient sanitization of parameters used for integer-mapped DAAP fields, enabling attackers to bypass filters and gain unauthorized access to media library data. The attack requires network access to the vulnerable DAAP service and appears to have low complexity, as it exploits straightforward parameter injection. The primary impact is confidentiality compromise, allowing unauthorized disclosure of media library information. The FAUCET Risk Score of 46.0/100 indicates moderate risk, though the EPSS score of 0.00036 suggests relatively low exploitation probability across the threat landscape. There is currently no indication of active exploitation in the wild. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog, and it remains inactive on threat tracking hot lists. No publicly available exploit code has been confirmed, and community attention appears minimal at this time. Organizations running affected OwnTone Server versions should prioritize patching to versions 29.1 or later to mitigate this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
>= 28.4.0, < 29.1.0CPE match
cpe:2.3:a:owntone:owntone_server:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.27%
Probability of exploitation in next 30 days
EPSS Percentile
19.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0027 is in the 9th percentile among its peer group of 23,703 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

github.com / owntone/owntone-server/commit/d4784ebf2099ed1a4203333aee957e5c7553c217
vulncheck.com / advisories/owntone-server-sql-injection-via-query-and-filter-parameters