CVE-2026-16224
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
20/07/2026
Description
A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The identifier of the patch is dc2b6910a423b3bfadeffaa303e1ba75cfb33900. Applying a patch is the recommended action to fix this issue.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/jxxghp/MoviePilot/
- https://github.com/jxxghp/MoviePilot/commit/dc2b6910a423b3bfadeffaa303e1ba75cfb33900
- https://github.com/jxxghp/MoviePilot/issues/5916
- https://vuldb.com/cve/CVE-2026-16224
- https://vuldb.com/submit/858227
- https://vuldb.com/vuln/380046
- https://vuldb.com/vuln/380046/cti



