CVE-2026-40349Disclosure(leepeuker / movary)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=true` to `PUT /settings/users/{userId}` for their own user ID. The endpoint is intended to let a user edit their own profile, but it updates the sensitive `isAdmin` field without any admin-only authorization check. Version 0.71.1 patches the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • movary

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
movary

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-04-18: 2Technical Details · 2026-04-18: 204-18
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-40349 Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to a… https://www.cve.org/CVERecord?id=CVE-2026-40349

    Post summary

    The post reports a privilege‑escalation flaw in Movary before version 0.71.1, providing basic technical details but no PoC, exploit, or patch information.

    0000089
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-40349 Privilege Escalation in Movary Prior to Version 0.71.1 via Admin Field Manipulation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40349

    Post summary

    CVE-2026-40349 is a disclosed privilege escalation vulnerability in Movary (pre‑0.71.1) that attackers can exploit by manipulating the admin field.

    0000047
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appleepeukermovary---

Explore more