โ† All reports

The Movary web application had multiple security vulnerabilities prior to version 0.71.1, allowing authenticated users to escalate their privileges and access sensitive user management endpoints.

CybersecurityApr 18, 2026score 0.173 posts ยท 0 replies across 1 instances
This thread discusses multiple vulnerabilities in the Movary web application, specifically related to unauthorized user privilege escalation and server-side request forgery. These vulnerabilities highlight security risks in self-hosted movie tracking software, emphasizing the need for timely updates and robust access controls.

Claims

The Movary web application had multiple security vulnerabilities prior to version 0.71.1, allowing authenticated users to escalate their privileges and access sensitive user management endpoints.
Parent: CybersecurityEntity: MovaryImpact: negativeDate: Apr 18, 2026Target: Security of Movary prior to version 0.71.1

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-23617 ๐Ÿ“Š Score: 7.7/10 (CVSS v3.1) ๐Ÿ“ฆ Product: movary ๐Ÿข Vendor: leepeuker ๐Ÿ“… Updated: 2026-04-18 ๐Ÿ“ Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server-side requests to arbitrary internal targets through `POST /settings/jellyfin/server-url-verify`. The endpoi... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23617 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23619 ๐Ÿ“Š Score: 8.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: movary ๐Ÿข Vendor: leepeuker ๐Ÿ“… Updated: 2026-04-18 ๐Ÿ“ Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=true` to `PUT /settings/users/{userId}` for their own user... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23619 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-23632 ๐Ÿ“Š Score: 8.8/10 (CVSS v3.1) ๐Ÿ“ฆ Product: movary ๐Ÿข Vendor: leepeuker ๐Ÿ“… Updated: 2026-04-18 ๐Ÿ“ Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use them to enumerate all users and create a new administrator ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-23632 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts ยท 0 favs ยท 0 replies ยท Apr 18, 2026
#cybersecurity#infosec#euvd#cve#vulnerability