CVE-2026-27792

Source
https://cve.org/CVERecord?id=CVE-2026-27792
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27792.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-27792
Aliases
  • GHSA-gx3h-3jg5-q65f
Published
2026-02-27T19:33:18.469Z
Modified
2026-03-03T02:56:42.575963Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Seerr missing authentication on pushSubscription endpoints
Details

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulnerability has been identified in the application starting in version 2.7.0 and prior to version 3.1.0. It allows authenticated users to access and modify data belonging to other users. This issue is due to the absence of the isOwnProfileOrAdmin() middleware on several push subscription API routes. Version 3.1.0 fixes the issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27792.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-862"
    ]
}
References

Affected packages

Git / github.com/seerr-team/seerr

Affected ranges

Type
GIT
Repo
https://github.com/seerr-team/seerr
Events

Affected versions

v2.*
v2.7.0
v2.7.1
v2.7.2
v2.7.3
v3.*
v3.0.0
v3.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27792.json"