Junglewise Threat Intelligence

CVE-2026-49247: Jellyfin path traversal in ClientLog Document endpoint

CVE-2026-49247 · Severity: high · CVSS 8.8 · Published 2026-06-24

Technologies: Jellyfin. Vendors: Jellyfin.

Executive brief

Jellyfin is an open-source media server used to manage and stream personal media collections. A security flaw allows logged-in users to bypass folder restrictions and write files to unauthorized locations on the server's hard drive. This could allow an attacker to corrupt system files or potentially gain further control over the server, impacting the privacy and availability of the media service.

Technical details

A path traversal vulnerability (CWE-22) exists in the POST /ClientLog/Document endpoint of Jellyfin media servers. The application fails to sanitize the 'Client' and 'Version' fields within the Authorization header, using them directly to construct file paths for log storage. An authenticated, non-privileged attacker can use directory traversal sequences (e.g., '../') to write arbitrary content to any location accessible by the Jellyfin service account, though the resulting file will have a forced '.log' extension. This issue is a regression of a previous fix (CVE-2023-30626) that was not correctly merged into the master branch. The vulnerability is resolved in version 10.11.10.

Affected products

  • Jellyfin Jellyfin >= 10.9.0, < 10.11.10

Timeline

  • 2026-06-10: advisory: GitHub Security Advisory published
  • 2026-06-24: disclosed: NVD publication date
  • 2026-06-24: patched: Fix released in version 10.11.10

References

Related threats