Authorization Bypass Vulnerability in MyTube by Franklioxygen
CVE-2026-24139
8.7HIGH
What is CVE-2026-24139?
MyTube, a self-hosted downloader and player for multiple video websites, has an authorization bypass vulnerability that affects versions up to 1.7.78. The flaw exists due to improper validation of user permissions on the database export endpoint. This allows unauthorized users, including those with low privileges, to download sensitive data from the application’s database. As a result, guest users can potentially access and export all user data, leading to serious privacy concerns. The issue necessitates immediate updates to safeguard sensitive information and ensure proper user access controls.
Affected Version(s)
MyTube < 1.7.79
