CVE-2026-32891Disclosure(openvessl / anchorr)

LOWCVSS 9.0 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector. Jellyseerr allows any account holder to execute arbitrary JavaScript in the Anchorr admin's browser session. The injected script calls the authenticated /api/config endpoint - which returns the full application configuration in plaintext. This allows the attacker to forge a valid Anchorr session token and gain full admin access to the dashboard with no knowledge of the admin password. The same response also exposes the API keys and tokens for every integrated service, resulting in simultaneous account takeover of the Jellyfin media server (via JELLYFIN_API_KEY), the Jellyseerr request manager (via JELLYSEERR_API_KEY), and the Discord bot (via DISCORD_TOKEN). This issue has been fixed in version 1.4.2.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-80CWE-212CWE-311

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • anchorr

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-03-20); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
anchorr

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-20: 4Mentions · 2026-03-22: 1PoC Mentioned / Linked · 2026-03-20: 1Technical Details · 2026-03-20: 4Technical Details · 2026-03-22: 103-2003-22
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-204
Disclosure3General1
2026-03-221
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    General

    CVE-2026-32891 Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a sto… https://www.cve.org/CVERecord?id=CVE-2026-32891

    Post summary

    The post notes a vulnerability in the Anchorr Discord bot affecting versions 1.4.1 and below, but it provides no PoC, exploit, patch, or evidence of active exploitation.

    00010327
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-32891 - Critical Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability... https://www.thehackerwire.com/vulnerability/CVE-2026-32891/ https://t.co/2NDLcIkrKE

    Post summary

    The post discloses a critical stored XSS flaw (CVE-2026-32891) in the Anchorr Discord bot, without mentioning a PoC, exploit tool, or patch details.

    0000031
    142 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32891: Anchorr Privilege Escalation: Je... Stored XSS in media bot turns any Jellyseerr user into full admin—one malicious request dumps all API keys, session tok... https://zerodaysignal.com/vulnerability/CVE-2026-32891 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE‑2026‑32891, a stored XSS in Jellyseerr’s media bot that leads to privilege escalation and credential theft, and provides a link potentially containing a PoC.

    0000049
    155 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32891 Stored XSS in Anchorr Discord Bot Leads to Complete Multi-Service Compromise https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32891

    Post summary

    The snippet announces a stored XSS vulnerability (CVE‑2026‑32891) in the Anchorr Discord Bot that could lead to multi‑service compromise, without providing PoC, exploit code, or patch details.

    0000051
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32891: CRITICAL] Anchorr Discord bot versions 1.4.1 and below are vulnerable to stored XSS in Jellyseerr user selector, enabling attackers to access plaintext config data and gain full admin access...#cve,CVE-2026-32891,#cybersecurity https://cvefind.com/CVE-2026-32891

    Post summary

    The post announces CVE-2026-32891, a critical stored XSS vulnerability in Anchorr Discord bot versions 1.4.1 and below, enabling attackers to read config data and gain full admin access; it provides technical details but no PoC, exploit tool, or patch information.

    00000265
    604 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenvesslanchorr---

Explore more