External risk intelligence

Wizarr Arbitrary Code Execution via Jinja2 Template Injection CVE-2026-108264

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-108264

Wizarr is designed to be an internet-facing application that manages invitations for media servers like Jellyfin, Plex, and Emby. Because its primary purpose is to provide an accessible interface for external users to join private media servers, the application is commonly deployed as an internet-facing web service.

Cross-site Scripting

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Wizarr system, which manages user invitations for media servers like Jellyfin and Plex, allows authenticated users to execute arbitrary code. This could lead to the disclosure of sensitive information, access to credentials, and the execution of operating system commands.

  • System allows unauthorized code execution.
  • Affects internet-facing invitation management.
  • Confirm relevance and exposure of system.

Attack Path

How an attacker could exploit the issue

An attacker could target the Wizarr system by crafting malicious Markdown content within wizard steps, either directly through the editor or by importing an untrusted bundle. This crafted content would be processed by the application's non-sandboxed Jinja2 environment, allowing for arbitrary Python code execution. The vulnerability can lead to the disclosure of sensitive information, access to connected service credentials and databases, and the execution of operating-system commands as the application user.

  • Authenticated user or administrator with import privilege.
  • Crafted Markdown in wizard steps or imported bundles.
  • Arbitrary code execution and data compromise.

Live Threat

Current exploitation, exposure, and threat context

An authenticated user with the ability to create wizard steps or import untrusted bundles could execute arbitrary Python code within the application's non-sandboxed environment. This could lead to the execution of operating-system commands, disclosure of sensitive information like the Flask SECRET_KEY and connected service credentials, and potential stored cross-site scripting vulnerabilities.

  • System commands and Flask SECRET_KEY.
  • Arbitrary Python execution via crafted wizard steps.
  • Compromise of credentials and server data.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Wizarr application's potential for arbitrary code execution and data compromise necessitates immediate action. Owners of media server deployments utilizing Wizarr, particularly those accessible externally, should prioritize identifying all instances of the affected technology, assessing their exposure, and confirming business criticality. This initial triage will inform the subsequent remediation planning, which may involve vendor coordination or temporary risk reduction measures.

  • Identify Wizarr instances and their owners.
  • Verify external reachability and business criticality.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Wizarr?

Wizarr is an invitation and management platform built to simplify how users join private media servers such as Jellyfin, Plex, and Emby. It acts as a bridge, providing a user-friendly interface that automates the onboarding process for new members.

What does CVE-2026-108264 mean?

This vulnerability is an instance of Improper Neutralization of Special Elements Used in a Template Engine, classified as CWE-1336. In simple terms, the application incorrectly handles Markdown text by processing it as active code rather than just plain content. Because the environment lacks necessary restrictions, this flaw allows stored text to trigger unauthorized Python commands.

How is this vulnerability triggered?

An attacker must be able to input or import malicious content into the wizard steps. This happens through the application's editor or by importing an untrusted bundle. Merely browsing the site or viewing legitimate steps will not trigger the bug; the system only executes the code when it attempts to render the specific, maliciously crafted step.

Is my Wizarr instance at risk?

Halo Surface Signal notes that Wizarr is inherently designed to be an internet-facing application, as its primary purpose is to provide an accessible portal for external users. Because of this, any instance exposed to the internet is a potential target. Administrators should prioritize checking their network configuration to see if their setup is reachable externally.

What is the first step to address this?

You should immediately identify all active instances of Wizarr within your environment. Once identified, confirm your current version and update to 2026.9.1 or later to apply the fix. Until you can update, you should restrict access to administrative functions like importing bundles or editing wizard steps.

References