CVE-2026-108264
Received Received - Intake

Remote Code Execution in Wizarr Media Server

Vulnerability report for CVE-2026-108264, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

Wizarr is an advanced user invitation and management system for Jellyfin, Plex, Emby, and other media servers. Prior to 2026.9.1, wizard step Markdown supplied through the editor or imported bundles was evaluated by app/blueprints/wizard/routes.py in the application's non-sandboxed Jinja2 environment with application globals exposed. An authenticated user able to create steps, or an administrator importing an untrusted bundle through POST /settings/wizard/import, could execute arbitrary Python when GET /wizard/{server}/{idx} rendered the stored step; app/jinja_filters.py and app/services/wizard_widgets.py contained additional evaluation sinks. This could execute operating-system commands as the application user, disclose the Flask SECRET_KEY, access connected service credentials and the database, and produce stored cross-site scripting. This issue is fixed in 2026.9.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-10
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wizarrrr wizarr < 2026.9.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1336 The product uses a template engine to insert or process externally-influenced input, but it does not neutralize or incorrectly neutralizes special elements or syntax that can be interpreted as template expressions or other code directives when processed by the engine.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Wizarr before version 2026.9.1 has a vulnerability where Markdown in wizard steps is processed using a non-sandboxed Jinja2 environment with exposed application globals. This allows authenticated users to execute arbitrary Python code when steps are rendered, potentially leading to command execution, data exposure, or cross-site scripting.

Detection Guidance

Check Wizarr version for versions prior to 2026.9.1. Inspect server logs for suspicious GET /wizard/{server}/{idx} requests or unusual activity in app/jinja_filters.py and app/services/wizard_widgets.py. Look for unauthorized access or data exfiltration patterns.

Impact Analysis

An attacker could gain control of the application server, access sensitive data like credentials or the database, execute system commands, or inject malicious scripts. This requires an authenticated user with step creation privileges or an admin importing untrusted bundles.

Compliance Impact

This vulnerability could lead to unauthorized data access or disclosure, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Organizations using affected versions may face compliance violations and potential fines.

Mitigation Strategies

Upgrade Wizarr to version 2026.9.1 or later immediately. Review and remove any untrusted steps or bundles in the wizard configuration. Rotate the Flask SECRET_KEY and audit connected service credentials for potential compromise.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108264. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart