CVE-2026-65696

MEDIUM

Overseerr 1.35.0 Authorization Bypass via pushSubscriptions API

Title source: cna
STIX 2.1

Description

Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId in the path parameters. Attackers can exploit the missing ownership check in the affected handlers to access target user records without the filteredFields filter, leaking sensitive data including email addresses and plexId values.

References (2)

Core 2
Core References
Exploit technical-description exploit
Researcher Disclosure
https://github.com/geo-chen/oss/blob/main/overseerr.md

Scores

CVSS v3 5.4
EPSS 0.0016
EPSS Percentile 6.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
sct/overseerr < 1.35.0
Published Jul 23, 2026
Tracked Since Jul 23, 2026