CVE Feed

    Dashboard / CVE / CVE-2026-58447

    CVE-2026-58447

    Invidious through 2.20260626.0, fixed in commit 77ad416, contains a broken object level authorization vulnerability that allows authenticated attackers to delete videos from other users' playlists by supplying an arbitrary global video index in the remove_video action of the playlist endpoint. Attackers can obtain per-video index values from the public playlist JSON API and submit them to the playlist video deletion endpoint without ownership validation, permanently removing videos from playlists they do not own.

    Published:Jun 30, 2026
    Last Modified:Jul 1, 2026
    EPS:Jun 30, 2026
    EPSS Score:0.00225
    CVSS Score:6.5

    Affected Products

    Vendor
    Iv-org
    Product
    Invidious
    Vendor
    Iv Org
    Product
    Invidious

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High