PT-2026-28518 · Mytube · Mytube

Daniel-Grunbergerca

·

Published

2026-03-27

·

Updated

2026-03-27

·

CVE-2026-33735

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MyTube versions prior to 1.8.69
Description MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.8.69, an authorization bypass exists in the /api/settings/import-database API endpoint. This bypass allows attackers with low-privilege credentials to upload and replace the application's SQLite database, resulting in a full compromise of the application. The bypass is also relevant for other POST routes.
Recommendations Versions prior to 1.8.69 should be updated to version 1.8.69 or later.

Exploit

Fix

IDOR

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-33735
GHSA-63CF-662X-CRP2

Affected Products

Mytube