CVE-2026-49247 - Jellyfin: Potential Authenticated path traversal in /ClientLog/Document
CVE ID :CVE-2026-49247 Published : June 24, 2026, 6:18 p.m. | 4 hours, 52 minutes ago Description :Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization header's Client and Version fields and uses them...