Sploitus

CVE-2026-27792

No indexed exploits for CVE-2026-27792 yet

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. A missing authorization vulnerability has been identified in the application starting in version 2.7.0 and prior to version 3.1.0. It allows authenticated users to access and modify data belonging to other users. This issue is due to the absence of the `isOwnProfileOrAdmin()` middleware on several push subscription API routes. Version 3.1.0 fixes the issue.

Affected products
Emby, Jellyfin, Plex, Seerr
Seerr
< 3.1.0
Fix
Available
CVSS 3.1
5.4 MEDIUM
EPSS
0.2% (12th percentile)
Weakness
CWE-862
NVD status
Analyzed
Published
2026-02-27
CVE-2026-27792 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-27792 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-27792 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.