CVE-2026-58447Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete videos from other users' playlists by supplying an arbitrary global video index in the remove_video action of the playlist endpoint. Attackers can obtain per-video index values from the public playlist JSON API and submit them to the playlist video deletion endpoint without ownership validation, permanently removing videos from playlists they do not own.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-30: 3Patch / Workaround · 2026-06-30: 2Technical Details · 2026-06-30: 306-30
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-58447 Broken Object Level Authorization in Invidious Through 2.20260626.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-58447

    Post summary

    This entry is a vulnerability disclosure notice for CVE‑2026‑58447 in Invidious, describing a broken object‑level authorization flaw in a specific version, with no mention of PoC, exploits, patches, or active exploitation.

    00000131
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-58447 Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete vide… https://www.cve.org/CVERecord?id=CVE-2026-58447 ----- Traducción: CVE-2026-58447 Inv… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-58447, a broken object-level authorization flaw in Invidious that permits authenticated deletions of videos, and notes it was fixed in commit 77ad416.

    0000038
    89 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-58447 Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete vide… https://www.cve.org/CVERecord?id=CVE-2026-58447

    Post summary

    CVE‑2026‑58447 is a broken object‑level authorization bug in Invidious that allows authenticated deletion of content; it has been fixed in commit 77ad416.

    00000617
    57.7K followersView on X

Explore more