Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 09 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 07 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lyrion
Lyrion lyrion Music Server |
|
| Vendors & Products |
Lyrion
Lyrion lyrion Music Server |
Fri, 05 Jun 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media directories and no authentication in the default configuration, allowing a remote, unauthenticated attacker to enumerate arbitrary locations on the host filesystem. | |
| Title | Lyrion Music Server 9.2.0 Arbitrary Directory Listing | |
| Weaknesses | CWE-548 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-09T14:37:46.385Z
Reserved: 2026-06-04T10:47:01.275Z
Link: CVE-2026-50233
Updated: 2026-06-09T13:43:41.492Z
Status : Deferred
Published: 2026-06-05T14:16:36.550
Modified: 2026-06-05T14:59:31.207
Link: CVE-2026-50233
No data.
OpenCVE Enrichment
Updated: 2026-06-07T11:16:52Z