CVE-2026-35031Disclosure(jellyfin / jellyfin)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversal via the file extension and enabling arbitrary file write. This arbitrary file write can be chained into arbitrary file read via .strm files, database extraction, admin privilege escalation, and ultimately remote code execution as root via ld.so.preload. Exploitation requires an administrator account or a user that has been explicitly granted the "Upload Subtitles" permission. This issue has been fixed in version 10.11.7. If users are unable to upgrade immediately, they can grant non-administrator users Subtitle upload permissions to reduce attack surface.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-22CWE-187

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jellyfin

Threat summary

  • Public PoC is present in monitored signal
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-15); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
jellyfin

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-04-15: 4Mentions · 2026-04-16: 1Mentions · 2026-04-18: 1PoC Mentioned / Linked · 2026-04-16: 1Technical Details · 2026-04-15: 4Technical Details · 2026-04-16: 104-1504-1604-18
Signal classification2 categories
Disclosure
466.7%
General
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-154
Disclosure3General1
2026-04-161
Disclosure1
2026-04-181
General1
Full discourse6 posts
  • Kerem 🛡 Cyber Security Engineer@keraattin
    Disclosure

    a critical RCE discovered in Jellyfin Media Server (CVE-2026-35031, CVSS 9.9). The subtitle upload endpoint doesn't validate the format field, allowing path traversal + arbitrary file write. This chains into database extraction, admin escalation, and root RCE. A 5-minute read thread below...

    Post summary

    The post announces the discovery of a critical remote code execution flaw in Jellyfin Media Server, outlining the attack vector and potential impact, but does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    1000094
    1.1K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-35031: Jellyfin Subtitle Upload Path Traversal Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q04cCCCS0

    Post summary

    The available text only contains a headline about Jellyfin’s path‑traversal vulnerability, with no details on PoC, exploitation, patches, or technical specifics.

    0000039
    29 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-35031: Jellyfin: Potential RCE via subt... Subtitle upload to root RCE via path traversal + .strm file chaining is a beautiful exploit primitive that turns media ... https://zerodaysignal.com/vulnerability/CVE-2026-35031 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a Jellyfin vulnerability (CVE-2026-35031) that can lead to remote code execution via path traversal and .strm file chaining, with a link suggesting a proof of concept exists.

    0000085
    218 followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-35031 | CVSS 9.9 🔴 CVE-2026-38526 | CVSS 9.9 🔴 CVE-2025-63939 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet lists three high‑CVSS CVEs and a link to a vulnerability portal, but does not include PoC, exploit details, active exploitation, or patch information.

    00000302
    5.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35031 Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Su… https://www.cve.org/CVERecord?id=CVE-2026-35031

    Post summary

    The text announces a known vulnerability in Jellyfin versions before 10.11.7, detailing its location in the subtitle upload endpoint, but does not provide PoC, exploit, patch, or evidence of active exploitation.

    00000104
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35031 Arbitrary File Write and Remote Code Execution in Jellyfin Prior ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35031 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces a newly identified vulnerability (CVE-2026-35031) in Jellyfin that permits arbitrary file writes and remote code execution, providing a link to details but no PoC, exploit code, or mitigation.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjellyfinjellyfin---

Explore more