What is CVE-2026-65696?
CVE-2026-65696: An authorization bypass vulnerability in Overseerr through version 1.35.0 allows any authenticated user to manipulate push subscriptions of other users by specifying their `userId` in the API path parameters. This enables listing, reading, and deleting sensitive push subscription data. Immediate patching beyond version 1.35.0 is strongly advised.
Azərbaycanca: CVE-2026-65696: Overseerr-in 1.35.0 versiyasına qədər push subscription API-də authorizasiya bypass zəifliyi aşkarlanıb. Autentifikasiya olunmuş istifadəçi, yol parametrlərində başqa bir istifadəçinin `userId`-ni göstərərək həmin şəxsin push abunəliklərini siyahıya ala, oxuya və silə bilər. Təcili olaraq ən son təhlükəsizlik yamasını tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What does the CVE-2026-65696 vulnerability in Overseerr allow attackers to do via the push subscription API?
Any authenticated user can list, read, and delete other users' push subscriptions by specifying their `userId` in the API path parameters.
Which versions of Overseerr are affected by CVE-2026-65696?
The vulnerability affects Overseerr through version 1.35.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.