Unrated severityNVD Advisory· Published Jul 19, 2026· Updated Jul 20, 2026
jxxghp MoviePilot Application API improper authorization
CVE-2026-16224
Description
A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The identifier of the patch is dc2b6910a423b3bfadeffaa303e1ba75cfb33900. Applying a patch is the recommended action to fix this issue.
Affected products
1- Range: <=2.13.5
Patches
Vulnerability mechanics
References
6- github.com/jxxghp/MoviePilot/commit/dc2b6910a423b3bfadeffaa303e1ba75cfb33900mitrepatch
- vuldb.com/cve/CVE-2026-16224mitrethird-party-advisory
- vuldb.com/submit/858227mitrethird-party-advisory
- github.com/jxxghp/MoviePilot/issues/5916mitreissue-tracking
- vuldb.com/vuln/380046mitrevdb-entry
- vuldb.com/vuln/380046/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.