Arbitrary Code Execution Vulnerability in Wizarr for Jellyfin and Plex
CVE-2026-108264

9.1CRITICAL

Key Information:

Vendor

Wizarrrr

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-108264?

Wizarr, an advanced user invitation and management system for media servers like Jellyfin and Plex, was found to have a serious vulnerability prior to version 2026.9.1. In this version, user-supplied Markdown content underwent evaluation in a non-sandboxed environment which exposed application globals. This flaw allowed authenticated users, including administrators importing untrusted bundles, to execute arbitrary Python code during the rendering of stored steps. This could lead to unauthorized operating system command execution, potential exposure of sensitive information like the Flask SECRET_KEY, access to service credentials, database leakage, and the possibility of stored cross-site scripting. Effective security measures have been implemented in version 2026.9.1 to mitigate this risk.

Affected Version(s)

wizarr < 2026.9.1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.