LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-40350

CVE-2026-40350 - Vulnerability Analysis

HighCVSS: 8.8

Last Updated: April 18, 2026

Movary - Broken Access Control

Published: April 18, 2026Updated: April 18, 2026Remote Exploitable

Overview

Movary < 0.71.1 contains a broken access control vulnerability caused by missing admin-only middleware and flawed authorization logic in user-management endpoints, letting authenticated users enumerate users and create admin accounts, exploit requires valid user session.

Severity & Score

Severity: High
CVSS Score: 8.8
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Authenticated users can create new administrator accounts, leading to full administrative control over the application.

Mitigation

Upgrade to version 0.71.1 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 18, 2026

🟠 CVE-2026-40350 - High (8.8) Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use them to enumerate all users and create a new admi... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-40350/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 18, 2026

🟠 CVE-2026-40350 - High (8.8) Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use them to enumerate all users and create a new admi... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-40350/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-40350
Severity
High
CVSS Score
8.8
Type
broken_access_control
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-863

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days