Generated remediation guidance and an executive summary. No account required.
MyTube is a self-hosted downloader and player for several video websites Prior to version 1.8.69, an authorization bypass in the `/api/settings/import-database` endpoint allows attackers with low-privilege credentials to upload and replace the application's SQLite database entirely, leading to a full compromise of the application. The bypass is relevant for other POST routes as well. Version 1.8.69 fixes the issue.
Cite this page
CVE-2026-33735. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2026-33735
Use CWE-285, Franklioxygen vendor hub and Mytube product page to widen CVE-2026-33735 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-23837, CVE-2026-33890 and CVE-2026-24139 for nearby disclosures in the same product family.