PT-2026-22381 · Seerr+3 · Seerr+3

Gauthier-Th

·

Published

2026-02-27

·

Updated

2026-03-04

·

CVE-2026-27792

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Seerr versions prior to 3.1.0
Description Seerr, an open-source media request and discovery manager for Jellyfin, Plex, and Emby, contains a flaw where authenticated users can access and modify data belonging to other users. This is due to the lack of the isOwnProfileOrAdmin() middleware on certain push subscription API routes.
Recommendations Update to version 3.1.0 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-27792
GHSA-GX3H-3JG5-Q65F

Affected Products

Emby
Jellyfin
Plex
Seerr