CVE-2026-35032Disclosure(jellyfin / jellyfin)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts), where the tuner URL is not validated, allowing local file read via non-HTTP paths and Server-Side Request Forgery (SSRF) via HTTP URLs. This is exploitable by any authenticated user because the EnableLiveTvManagement permission defaults to true for all new users. An attacker can chain these vulnerabilities by adding an M3U tuner pointing to an attacker-controlled server, serving a crafted M3U with a channel pointing to the Jellyfin database, exfiltrating the database to extract admin session tokens, and escalating to admin privileges. This issue has been fixed in version 10.11.7. If users are unable to upgrade immediately, they can disable Live TV Management privileges for all users.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-73CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jellyfin

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
jellyfin

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-15: 2Technical Details · 2026-04-15: 204-15
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-35032 Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /LiveTv/TunerHosts… https://www.cve.org/CVERecord?id=CVE-2026-35032

    Post summary

    The text announces CVE-2026-35032 affecting Jellyfin versions before 10.11.7, describing a vulnerability chain in the LiveTV M3U tuner endpoint, but does not include a PoC, exploit, or patch information.

    00000132
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-35032 Local File Read and SSRF in Jellyfin LiveTV M3U Tuner Endpoint Below 10.11.7 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35032

    Post summary

    The text announces CVE-2026-35032, highlighting a local file read and SSRF vulnerability in Jellyfin LiveTV M3U Tuner endpoint for versions below 10.11.7, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000083
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjellyfinjellyfin---

Explore more