CVE-2026-78051CWE-425CWE-552

CVE-2026-78051

Medium · published August 23, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
33.8
In the wild
Unconfirmed
What it is

A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies.txt of the component Cookie File Handler. This manipulation causes files or directories accessible. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2026.06.20 is sufficient to resolve this issue. Patch name: ce897ee00903bf7ded406f0d7852d95dd4164add. You should upgrade the affected component.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v4.0
6.9 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
EPSS
0.00405 · 33.8th percentile
Weaknesses
CWE-425 · Direct Request ('Forced Browsing'); CWE-552 · Files or Directories Accessible to External Parties
Published
2026-08-23T04:16Z
References (6)
EPSS history
Timeline
  • 22 AUG 23:30Z
    alexta69 MeTube Cookie File cookies.txt file access
    cvelistv5