CVE-2026-65696
MEDIUMOverseerr 1.35.0 Authorization Bypass via pushSubscriptions API
Title source: cnaDescription
Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId in the path parameters. Attackers can exploit the missing ownership check in the affected handlers to access target user records without the filteredFields filter, leaking sensitive data including email addresses and plexId values.
References (2)
Core 2
Core References
Exploit technical-description
exploit
Researcher Disclosure
https://github.com/geo-chen/oss/blob/main/overseerr.md
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/overseerr-authorization-bypass-via-pushsubscriptions-api
Scores
CVSS v3
5.4
EPSS
0.0016
EPSS Percentile
6.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-639
Status
published
Products (1)
sct/overseerr
< 1.35.0
Published
Jul 23, 2026
Tracked Since
Jul 23, 2026