CVE-2026-49220

MEDIUM CVSS 3.1: 5.7 EPSS 0.33%
Updated Jun 25, 2026
Jellyfin
Parameter Value
CVSS 5.7 (MEDIUM)
Fixed In 10.11.9
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor Jellyfin
Public PoC No

Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which can allow a non-privileged user to execute arbitrary Javascript in the context of a logged-in Administrative user, resulting in numerous potential issues. The Client header during an AuthenticateByName can contain arbitrary HTML and Javascript, which will then be executed by the Administrative user when visiting the Access tab of the user in question from within the dashboard.

This vulnerability is fixed in 10.11.9.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1