CVE-2025-32012 | Jellyfin up to 10.10.6 Endpoint /System/Restart authentication spoofing
A vulnerability, which was classified as critical, has been found in Jellyfin up to 10.10.6. Impacted is an unknown function of the file /System/Restart of the component Endpoint. This manipulation causes authentication bypass by spoofing.
This vulnerability is tracked as CVE-2025-32012. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.