References https://www.vulncheck.com/advisories/lyrion-music-server-arbitrary-directory-listing https://radar.offseq.com/threat/cve-2026-50233-exposure-of-information-through-dir-3dbda2d0 https://www.tenable.com/cve/CVE-2026-50233 https://www.zeroscience.mk/advisories/ZSL-2026-5991.html https://vuldb.com/vuln/368921 https://vulners.com/cve/CVE-2026-50233 https://cve.yack.one/cve/CVE-2026-50233 https://github.com/advisories/GHSA-36hm-c9f8-f8xc https://nvd.nist.gov/vuln/detail/CVE-2026-50233 https://www.cyber-defence.io/tools/cve/CVE-2026-50233
Related VulnerabilitiesPoCCVE-2026-27960: OpenCTI < 6.9.13 - Authentication Bypass via User ImpersonationPoCCVE-2020-29134: TOTVS Fluig <= 1.7.0 - Arbitrary File ReadPoCCVE-2023-54391: Proxmox VE - Default Credentials with TFA BypassPoCCVE-2026-19092: Tutor LMS < 4.0.6 - Unauthenticated Arbitrary PHP Function InvocationPoCCVE-2026-19632: TranslatePress <= 3.3.1 - Unauthenticated Account TakeoverPoCCVE-2026-23693: ElementsKit Lite <3.7.9 - Unauthenticated Mailchimp ProxyPoCCVE-2026-29962: HSC MailInspector - Local File InclusionPoCCVE-2026-29963: HSC MailInspector - Unauthenticated Arbitrary File ReadPoCCVE-2026-30849: MantisBT < 2.28.1 - SOAP API Authentication BypassPoCCVE-2026-41679: Paperclip - Remote Code ExecutionPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalPoCCVE-2026-53595: FreeScout < 1.8.224 - Invite Hash Authorization BypassPoCCVE-2026-56292: AcyMailing < 10.11.1 - Unauthenticated SQL Injection