CVE-2026-35031HIGH 8.8EPSS p50.2%

CVE-2026-35031CVE-2026-35031

Description

Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /Videos/{itemId}/Subtitles), where the Format field is not validated, allowing path traversal via the file extension and enabling arbitrary file write. This arbitrary file write can be chained into arbitrary file read via .strm files, database extraction, admin privilege escalation, and ultimately remote code execution as root via ld.so.preload. Exploitation requires an administrator account or a user that has been explicitly granted the "Upload Subtitles" permission. This issue has been fixed in version 10.11.7. If users are unable to upgrade immediately, they can grant non-administrator users Subtitle upload permissions to reduce attack surface.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS0.75% probability of exploitation · percentile 50.2% · 2026-06-18T12:00:27Z
Published2026-04-14
Last modified2026-04-23

Underlying weaknesses· 3

CWE-20CWE-22CWE-187

References

  1. https://github.com/jellyfin/jellyfin/releases/tag/v10.11.7
  2. https://github.com/jellyfin/jellyfin/security/advisories/GHSA-j2hf-x4q5-47j3

3

TypeTargetConfidenceTier
WeaknessPartial String Comparisoncwe-1870%live
WeaknessImproper Input Validationcwe-200%live
WeaknessImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-220%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-35033
CVE
CVE-2026-35032
CVE
CVE-2025-31499
CVE
CVE-2025-24960
CVE
CVE-2026-41167
CVE
CVE-2026-36760
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.