CVE 8.8 HIGH

Jellyfin: Potential Authenticated path traversal in /ClientLog/Document_CVE-2026-49247

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization header's Client and Version fields and uses them unsanitized as components of the on-disk filename when persisting client-uploaded log documents. As a result, any authenticated non-admin user can include ../ sequences in the Client field to cause Jellyfin to write attacker-controlled content to arbitrary paths reachable by the Jellyfin service user, with a forced .log suffix. This vulnerability is fixed in 10.11.10.

AI Analysis

Authenticated path traversal vulnerability in Jellyfin's /ClientLog/Document endpoint, allowing attackers to write arbitrary files with a .log suffix.

Basic Information

ID CVE-2026-49247
Source GitHub_M
Published Jun 24, 2026 at 18:18

Affected Product

Vendor jellyfin
Product jellyfin
Version >= 10.9.0, < 10.11.10
Affected Versions jellyfin jellyfin >= 10.9.0, < 10.11.10

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor Jellyfin
Product Jellyfin Media Server
Version 10.9.0 to 10.11.10

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.