PT-2026-32956 · Jellyfin · Jellyfin

·

CVE-2026-35031

·

Published

2026-04-14

·

Updated

2026-05-22

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jellyfin versions prior to 10.11.7
Description A flaw exists in the subtitle upload endpoint '/Videos/{itemId}/Subtitles' where the Format field is not validated. This allows path traversal via the file extension, enabling arbitrary file write. This can be chained to achieve arbitrary file read via .strm files, database extraction, admin privilege escalation, and remote code execution as root via ld.so.preload. Exploitation requires an administrator account or a user explicitly granted the Upload Subtitles permission.
Recommendations Update to version 10.11.7. Restrict the Upload Subtitles permission for non-administrator users to reduce the attack surface.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35031
GHSA-J2HF-X4Q5-47J3

Affected Products

Jellyfin