Authorization Bypass in MyTube Allows Database Compromise
CVE-2026-33735
7.4HIGH
What is CVE-2026-33735?
MyTube, a self-hosted downloader for video websites, has a vulnerability in its /api/settings/import-database endpoint that allows users with low-privilege credentials to bypass authorization. This flaw enables these users to upload and entirely replace the application's SQLite database, potentially leading to a complete compromise of the application. The issue also affects other POST routes within the application. An update to version 1.8.69 addresses this vulnerability effectively.
Affected Version(s)
MyTube < 1.8.69
