Unauthorized Access Vulnerability in Kyoo Media Server
CVE-2026-77385

4.3MEDIUM

Key Information:

Vendor

Zoriya

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-77385?

Kyoo, a self-hosted media server designed for managing movies, series, and anime, is susceptible to an unauthorized access vulnerability. This issue arises when registered users with the core.play permission can provide a base64-encoded filesystem path to the transcoder. The path validation process only ensures the path begins with Settings.SafePath, neglecting to verify a corresponding Kyoo catalog record. Consequently, users can access hidden, temporary, or non-cataloged files within the media directory if they know or can guess the path. This vulnerability was resolved in version 5.1.0.

Affected Version(s)

Kyoo < 5.1.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.