CVE-2026-33735
HIGHMyTube has an Improper Access Control that Allows Complete Application Takeover
Title source: cnaDescription
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows attackers with low-privilege credentials to upload and replace the application's SQLite database entirely, leading to a full compromise of the application. The bypass is relevant for other POST routes as well. Version 1.8.69 fixes the issue.
References (3)
Scores
CVSS v3
8.8
EPSS
0.0004
EPSS Percentile
13.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-285
CWE-639
Status
published
Products (2)
franklioxygen/mytube
< 1.8.69
franklioxygen/MyTube
< 1.8.69
Published
Mar 27, 2026
Tracked Since
Mar 27, 2026