Unauthenticated Access Flaw in MyTube Allows Full Admin Compromise
CVE-2026-33890
8.9HIGH
What is CVE-2026-33890?
MyTube, a self-hosted downloader and player for various video websites, contains a vulnerability that permits unauthenticated attackers to register arbitrary passkeys. This security flaw provides full administrative access to the application, as the passkey registration endpoint does not require prior authentication. As a result, any successfully registered passkey can instantly grant admin privileges, leading to complete compromise of the application. Users are strongly advised to upgrade to version 1.8.71 to mitigate this risk.
Affected Version(s)
MyTube < 1.8.71
