CVE-2026-65696 | geo-chen Overseerr up to 1.35.0 Push Subscription API userId authorization
A vulnerability described as critical has been identified in geo-chen Overseerr up to 1.35.0. This affects an unknown part of the component Push Subscription API. The manipulation of the argument userId results in authorization bypass. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2026-65696. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More