Description
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitrary passkey and subsequently authenticate with it to obtain a full admin session. The application exposes passkey registration endpoints without requiring prior authentication. Any successfully authenticated passkey is automatically granted an administrator token, allowing full administrative access to the application. This enables a complete compromise of the application without requiring any existing credentials. Version 1.8.71 fixes the issue.
Published: 2026-03-27
Score: 8.9 High
EPSS: < 1% Very Low
KEV: No
Impact: Admin Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

MyTube is a self-hosted downloader and media player that, before version 1.8.71, allowed an unauthenticated attacker to register any desired passkey through exposed endpoints. Once registered, the passkey could be used to authenticate and automatically receive an administrator token, granting full control of the application. This weakness corresponds to CWE‑284 (Improper Access Control) and carries a CVSS score of 8.9, indicating significant risk if exploited.

Affected Systems

The flaw impacts the FrankLioxygen MyTube application, specifically all releases prior to 1.8.71. Users running version 1.8.70 or earlier are vulnerable; upgrading to 1.8.71 or later removes the attack surface.

Risk and Exploitability

With the attack path available over publicly reachable HTTP endpoints and no authentication required, the vulnerability is easily exploitable over the network. The EPSS score of less than 1% suggests a low current exploitation frequency, but the lack of prior credential requirement and the full administrative takeover make it a high severity risk. The vulnerability is not listed in the CISA KEV catalog at this time, yet its potential impact warrants immediate attention.

Generated by OpenCVE AI on April 2, 2026 at 04:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade MyTube to version 1.8.71 or later.
  • Verify that the application is not publicly exposed or restrict access to the passkey registration endpoints via network firewall or authentication proxy.
  • Monitor application logs for suspicious passkey registration attempts.
  • Keep the system and dependencies updated to prevent related security issues.

Generated by OpenCVE AI on April 2, 2026 at 04:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:franklioxygen:mytube:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 27 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Mar 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Franklioxygen
Franklioxygen mytube
Vendors & Products Franklioxygen
Franklioxygen mytube

Fri, 27 Mar 2026 04:00:00 +0000

Type Values Removed Values Added
Description MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitrary passkey and subsequently authenticate with it to obtain a full admin session. The application exposes passkey registration endpoints without requiring prior authentication. Any successfully authenticated passkey is automatically granted an administrator token, allowing full administrative access to the application. This enables a complete compromise of the application without requiring any existing credentials. Version 1.8.71 fixes the issue.
Title MyTube has an Unauthenticated Admin Privilege Escalation via Passkey Registration
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Franklioxygen Mytube
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-27T13:49:59.015Z

Reserved: 2026-03-24T15:10:05.682Z

Link: CVE-2026-33890

cve-icon Vulnrichment

Updated: 2026-03-27T13:19:01.769Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-27T01:16:21.493

Modified: 2026-04-01T13:44:03.137

Link: CVE-2026-33890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-02T07:55:50Z

Weaknesses