CVE-2026-41167
Attacker can take control of your Jellyfin server by exploiting Jellystat
Halo Surface Signal: 2 out of 5 — less likely to be public-facing.
An internal attacker can exploit a flaw in Jellystat to steal administrative credentials and run unauthorized commands on the server. This could lead to a full system compromise and the exposure of sensitive database contents.