← Vulnerability feed

Vulnerability record · CVE-2026-33735 · published 27 March 2026

CVE-2026-33735: Franklioxygen mytube improper authorization vulnerability

FFranklioxygen · Mytube

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows attackers with low-privilege credentials to upload and replace the application's SQLite database entirely, leading to a full compromise of the application. The bypass is relevant for other POST routes as well. Version 1.8.69 fixes the issue.

7.4 CVSS 4.0 High EPSS 0.59% · top 54.2% CWE-285 · Improper authorizationCWE-639 · Insecure direct object reference
7.4CVSS 4.0 base score
0.59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows attackers with low-privilege credentials to upload and replace the application's SQLite database entirely, leading to a full compromise of the application. The bypass is relevant for other POST routes as well. Version 1.8.69 fixes the issue.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33735 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-23837Franklioxygen mytube incorrect authorization vulnerabilityMyTube is a self-hosted downloader and player for several video websites. A vulnerability present in version 1.7.65 and poetntially earlier versions …EPSS 0.65%8.9CVE-2026-33890Franklioxygen mytube improper access control vulnerabilityMyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitra…EPSS 0.70%8.7CVE-2026-24139Franklioxygen mytube missing authorization vulnerabilityMyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below do not safeguard against authorization bypass, al…EPSS 0.36%7.7CVE-2026-33935Franklioxygen mytube improper restriction of authentication attempts vulnerabilityMyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.72, an unauthenticated attacker can lock out administra…EPSS 0.80%5.3CVE-2026-24140Franklioxygen mytube mass assignment vulnerabilityMyTube is a self-hosted downloader and player for several video websites. Versions 1.7.78 and below have a Mass Assignment vulnerability in the setti…EPSS 0.33%5.3CVE-2026-23848Franklioxygen mytube vulnerabilityMyTube is a self-hosted downloader and player for several video websites. Prior to version 1.7.71, a rate limiting bypass via `X-Forwarded-For` heade…EPSS 0.36%8.8CVE-2026-58704Android Cellular Modem improper authorization allows adjacent privilege escalationAndroid's Cellular Modem component contains a logic error that bypasses permission checks, allowing an attacker within radio/adjacent range to escala…KEVEPSS 0.59%analysed9.8CVE-2021-28799QNAP HBS 3 improper authorization allows remote loginQNAP Hybrid Backup Sync 3 (HBS 3) contains an improper authorization flaw that lets remote attackers log in to the NAS device. The issue affects mult…KEVEPSS 78%analysed

Source: NIST National Vulnerability Database (record CVE-2026-33735), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.