Unauthenticated Access Flaw in MyTube Allows Full Admin Compromise
CVE-2026-33890

8.9HIGH

Key Information:

Status
Vendor
CVE Published:
27 March 2026

What is CVE-2026-33890?

MyTube, a self-hosted downloader and player for various video websites, contains a vulnerability that permits unauthenticated attackers to register arbitrary passkeys. This security flaw provides full administrative access to the application, as the passkey registration endpoint does not require prior authentication. As a result, any successfully registered passkey can instantly grant admin privileges, leading to complete compromise of the application. Users are strongly advised to upgrade to version 1.8.71 to mitigate this risk.

Affected Version(s)

MyTube < 1.8.71

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.