CVE-2026-49246: Jellyfin: Potential MKV attachment filename path traversal to RCE

Published Jun 24, 2026
·
Updated

Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forged filename tags can be leveraged to exploit missing path sanitization during playback. Jellyfin treats the MKV file name tag on MKV attachments as trusted and passes it unsanitized into Path.Combine(attachmentFolder, fileName) inside PathManager.GetAttachmentPath. Because .NET's Path.Combine neither normalises .. nor rejects a rooted second argument, a crafted MKV can redirect Jellyfin's MKV attachment extraction to any absolute path on disk. This triggers on any playback action of the affected video on a client which will attempt to burn in the subtitles by default.g This vulnerability is fixed in 10.11.10.

Affected Software

1 affected component
Jellyfin Jellyfin<10.11.10

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Jellyfin to a version that resolves this vulnerability.

    Fixed in 10.11.10
  2. Compensating control

    Until upgraded, restrict access so clients cannot trigger playback of affected MKV files (e.g., block untrusted MKV uploads/paths or deny playback to clients/users who could supply crafted MKVs).

Event History

Jun 24, 2026
CVE Published
via MITRE·06:21 PM
Data Sourced
via MITRE·06:21 PM
DescriptionWeakness
Data Sourced
via NVD·07:17 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-49246?

CVE-2026-49246 has a risk rating of 76, indicating a high severity threat.

2

How do I fix CVE-2026-49246?

To fix CVE-2026-49246, update Jellyfin to version 10.11.10 or later, which includes the necessary path sanitization improvements.

3

What vulnerability does CVE-2026-49246 describe?

CVE-2026-49246 describes a potential path traversal vulnerability in Jellyfin that can lead to remote code execution via specially crafted MKV attachments.

4

Which versions of Jellyfin are affected by CVE-2026-49246?

Jellyfin versions prior to 10.11.10 are affected by CVE-2026-49246.

5

What type of attack is CVE-2026-49246 associated with?

CVE-2026-49246 is associated with a path traversal attack that exploits unsanitized filename tags in MKV attachments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203