PT-2026-28518 · Mytube · Mytube

·

CVE-2026-33735

·

Published

2026-03-27

·

Updated

2026-03-27

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MyTube versions prior to 1.8.69
Description MyTube is a self-hosted downloader and player for several video websites. Prior to version 1.8.69, an authorization bypass exists in the /api/settings/import-database API endpoint. This bypass allows attackers with low-privilege credentials to upload and replace the application's SQLite database, resulting in a full compromise of the application. The bypass is also relevant for other POST routes.
Recommendations Versions prior to 1.8.69 should be updated to version 1.8.69 or later.

Exploit

Fix

IDOR

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33735
GHSA-63CF-662X-CRP2

Affected Products

Mytube