CVE-2026-27707 | seerr-team seerr up to 3.0.x /api/v1/auth/jellyfin authentication bypass (GHSA-rc4w-7m3r-c2f7 / EUVD-2026-9052)
A vulnerability has been found in seerr-team seerr up to 3.0.x and classified as critical. This vulnerability affects unknown code of the file /api/v1/auth/jellyfin. The manipulation leads to authentication bypass using alternate channel.
This vulnerability is uniquely identified as CVE-2026-27707. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.