VYPR
Medium severity5.4NVD Advisory· Published Feb 27, 2026· Updated Jun 17, 2026

CVE-2026-27792

CVE-2026-27792

Description

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulnerability has been identified in the application starting in version 2.7.0 and prior to version 3.1.0. It allows authenticated users to access and modify data belonging to other users. This issue is due to the absence of the isOwnProfileOrAdmin() middleware on several push subscription API routes. Version 3.1.0 fixes the issue.

Affected products

3
  • Seerr/Seerrllm-fuzzy2 versions
    <3.1.0, >=2.7.0+ 1 more
    • (no CPE)range: <3.1.0, >=2.7.0
    • cpe:2.3:a:seerr:seerr:*:*:*:*:*:*:*:*range: >=2.7.0,<3.1.0
  • seerr-team/seerrv5
    Range: >= 2.7.0, < 3.1.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.