CVE-2026-23837 | franklioxygen MyTube up to 1.7.65 /api/settings next authorization (GHSA-cmvj-g69f-8664 / EUVD-2026-3289)
A vulnerability labeled as critical has been found in franklioxygen MyTube up to 1.7.65. This issue affects the function Next of the file /api/settings. The manipulation results in incorrect authorization.
This vulnerability is reported as CVE-2026-23837. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.