CVE-2026-35033
A security flaw in Jellyfin media servers allows unauthorized users to read sensitive files from the server. This happens because the software fails to properly validate certain input parameters used when processing video streams.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running Jellyfin media server versions prior to 10.11.7.
Real-world impact
An attacker could potentially read sensitive system files, such as password files, by tricking the server into rendering the file contents directly into a video stream.
Why this severity
This vulnerability is rated as critical because it allows an attacker to access sensitive files without needing a username or password, and it can be executed remotely over a network.
What to do about it
- 01Upgrade Jellyfin to version 10.11.7 or later.
NVD-referenced vendor advisory
Timeline
- Apr 14, 2026 · Apr 14, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.
- Jul 26, 2026 · 10d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/jellyfin/jellyfin/releases/…productrelease notes
- github.com/jellyfin/jellyfin/security/…vendor advisory