CVE-2026-33890 Details
Description
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.71, an unauthenticated attacker can register an arbitrary passkey and subsequently authenticate with it to obtain a full admin session. The application exposes passkey registration endpoints without requiring prior authentication. Any successfully authenticated passkey is automatically granted an administrator token, allowing full administrative access to the application. This enables a complete compromise of the application without requiring any existing credentials. Version 1.8.71 fixes the issue.
A vulnerability in MyTube, a self-hosted video downloader and player, prior to version 1.8.71, allows an unauthenticated attacker to register a passkey and gain full administrative access. The application exposes passkey registration endpoints without requiring authentication. Once a passkey is registered, it is automatically granted an admin token, enabling complete compromise of the application. This vulnerability arises from the lack of authentication on critical passkey management endpoints, including registration and verification.
Users are advised to update to MyTube version 1.8.71 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/franklioxygen/MyTube/security/advisories/GHSA-378w-xh68-qrc8 | CISA-ADP | ExploitVendor Advisory |
| https://github.com/franklioxygen/MyTube/commit/d6c1275a7ff7ffd3d51b53c333237f4d572580ac | [email protected] | Patch |
| https://github.com/franklioxygen/MyTube/security/advisories/GHSA-378w-xh68-qrc8 | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| franklioxygen mytube | < 1.8.71 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 1, 2026 | Initial Analysis | [email protected] |
| Mar 27, 2026 | CVE Modified | CISA-ADP |
| Mar 27, 2026 | New CVE Received | [email protected] |