CVE-2026-65696:Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip
Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenticated users to list, read, and delete any other user's push subscriptions by supplying an arbitrary userId