VYPR
High severity7.3NVD Advisory· Published Feb 27, 2026· Updated Jun 17, 2026

CVE-2026-27707

CVE-2026-27707

Description

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Starting in version 2.0.0 and prior to version 3.1.0, an authentication guard logic flaw in POST /api/v1/auth/jellyfin allows an unauthenticated attacker to register a new Seerr account on any Plex-configured instance by authenticating with an attacker-controlled Jellyfin server. The attacker receives an authenticated session and can immediately use the application with default permissions, including the ability to submit media requests to Radarr/Sonarr. Any Seerr deployment where all three of the following are true may be vulnerable: settings.main.mediaServerType is set to PLEX (the most common deployment).; settings.jellyfin.ip is set to "" (default, meaning Jellyfin was never configured); and settings.main.newPlexLogin is set to true (default). Jellyfin-configured and Emby-configured deployments are not affected. Version 3.1.0 of Seerr fixes this issue.

Affected products

3
  • Seerr/Seerr2 versions
    cpe:2.3:a:seerr:seerr:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:seerr:seerr:*:*:*:*:*:*:*:*range: >=2.0.0,<3.1.0
    • (no CPE)range: >=2.0.0,<3.1.0
  • seerr-team/seerrv5
    Range: >= 2.0.0, < 3.1.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.