CVE-2026-50233 Details
Description
Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media directories and no authentication in the default configuration, allowing a remote, unauthenticated attacker to enumerate arbitrary locations on the host filesystem.
An arbitrary directory listing vulnerability has been identified in Lyrion Music Server version 9.2.0. This vulnerability exists in the readdirectory query, which is accessible through the Command Line Interface (CLI) service on TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The readdirectory query accepts a folder parameter and lists its contents without any restrictions to the configured media directories. In the default configuration, there is no authentication required, allowing remote, unauthenticated attackers to enumerate arbitrary locations on the host filesystem.
Users are advised to update to a version of Lyrion Music Server that addresses this vulnerability. The vendor has indicated that they are working on fixes and improving security defaults.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 5, 2026CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.vulncheck.com/advisories/lyrion-music-server-arbitrary-directory-listing | [email protected] | Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2026-5991.php | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-548 | Exposure of Information Through Directory Listing | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Lyrion Music Server | <= 9.2.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | New CVE Received | [email protected] |
Volerion