CVE-2026-16224: Jxxghp Moviepilot
Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability was identified in jxxghp MoviePilot up to 2.13.5. The affected element is an unknown function of the file /jxxghp/MoviePilot of the component Application API. The manipulation leads to improper authorization. Remote exploitation of the attack is possible. The identifier of the patch is dc2b6910a423b3bfadeffaa303e1ba75cfb33900. Applying a patch is the recommended action to fix this issue.
Affected products
- Jxxghp Moviepilot: version 2.13.0 only; version 2.13.1 only; version 2.13.2 only; version 2.13.3 only; version 2.13.4 only; version 2.13.5 only
Published 2026-07-19. Last modified 2026-07-20.