CVE-2026-33735 PUBLISHED

MyTube has an Improper Access Control that Allows Complete Application Takeover

Assigner: GitHub_M
Reserved: 23.03.2026 Published: 27.03.2026 Updated: 27.03.2026

MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the /api/settings/import-database endpoint allows attackers with low-privilege credentials to upload and replace the application's SQLite database entirely, leading to a full compromise of the application. The bypass is relevant for other POST routes as well. Version 1.8.69 fixes the issue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVSS Score: 7.4

Product Status

Vendor franklioxygen
Product MyTube
Versions
  • Version < 1.8.69 is affected

References

Problem Types

  • CWE-285: Improper Authorization CWE
  • CWE-639: Authorization Bypass Through User-Controlled Key CWE