References https://www.vulncheck.com/advisories/lyrion-music-server-arbitrary-directory-listing https://radar.offseq.com/threat/cve-2026-50233-exposure-of-information-through-dir-3dbda2d0 https://www.tenable.com/cve/CVE-2026-50233 https://www.zeroscience.mk/advisories/ZSL-2026-5991.html https://vuldb.com/vuln/368921 https://vulners.com/cve/CVE-2026-50233 https://cve.yack.one/cve/CVE-2026-50233 https://github.com/advisories/GHSA-36hm-c9f8-f8xc https://nvd.nist.gov/vuln/detail/CVE-2026-50233 https://www.cyber-defence.io/tools/cve/CVE-2026-50233
Related VulnerabilitiesPoCCVE-2022-27925: Zimbra Collaboration Suite 8.8.15/9.0 - Zip Path TraversalPoCCVE-2026-0692: BlueSnap Payment Gateway for WooCommerce <=3.4.0 - IPN Authorization BypassPoCCVE-2026-21589: Atlassian Jira/Confluence/Bitbucket - Pre-Auth Arbitrary File ReadPoCCVE-2026-29058: WWBN AVideo Encoder < 7.0 - Unauthenticated OS Command InjectionPoCCVE-2026-49468: LiteLLM Proxy < 1.84.0 - Host Header Authentication BypassPoCCVE-2025-62593: Ray < 2.52.0 - Remote Code ExecutionPoCCVE-2026-56681: 9router <=0.5.4 - Authentication BypassPoCCVE-2026-87902: WordPress Core - PHP Template Path TraversalPoCCVE-2026-89013: Dolibarr < 24.0.0 - Authorization Bypass via hashp ParameterPoCCVE-2026-89063: Bookly <=28.1 - IDOR Unauthenticated Sensitive Data Access关于U9 cloud存在命令执行漏洞的安全通告关于U9 cloud存在接口反序列化漏洞的安全通告PoCCVE-2026-49060: Hippoo Mobile App for WooCommerce - Broken Access Control