9.9
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
CVE-2026-35031: Jellyfin Subtitle Upload Path Traversal to RCE TL;DR A critical path traversal vulnerability in Jellyfin Media Server allows authenticated users with "Upload Subtitles" permission to upload files to arbitrary locations on disk. By...
Basic Information
ID
94F85AA7-B15A-5950-8EE5-C03E37FF8A2D
Published
Apr 15, 2026 at 20:56
Modified
Apr 15, 2026 at 20:57