Information Disclosure Vulnerability in MediaCMS by MediaCMS-IO
CVE-2026-65054
8.2HIGH
What is CVE-2026-65054?
MediaCMS version 8.2.0 has a vulnerability that allows authenticated users to inadvertently access private media metadata belonging to other users. By exploiting a flaw in the playlist API, attackers can add arbitrary media tokens to their playlists without proper access controls. This vulnerability permits users to issue PUT requests to the playlist API endpoint, enabling them to bypass critical ownership checks. As a result, attackers can access sensitive information, such as media titles, descriptions, view and like counts, file sizes, author usernames, and encoding statuses through an unfiltered data retrieval process.
Affected Version(s)
MediaCMS 8.2.0
