A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The identifier of the patch is dc2b6910a423b3bfadeffaa303e1ba75cfb33900. Applying a patch is the recommended action to fix this issue.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/16xxx/CVE-2026-16224.json",
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-266",
"CWE-285"
]
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "2.13.0"
},
{
"last_affected": "2.13.0"
},
{
"introduced": "2.13.1"
},
{
"last_affected": "2.13.1"
},
{
"introduced": "2.13.2"
},
{
"last_affected": "2.13.2"
},
{
"introduced": "2.13.3"
},
{
"last_affected": "2.13.3"
},
{
"introduced": "2.13.4"
},
{
"last_affected": "2.13.4"
},
{
"introduced": "2.13.5"
},
{
"last_affected": "2.13.5"
}
]
}