Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19986— Adblock for Youtube Extension Event Listener contentscript.js updateDynamicRules improper authorization

CVSS 5.4 · Medium EPSS 0.24% · P16

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 2

VendorProductVersion RangeStatus
n/aAdblock for Youtube Extension7.2.0affected
7.2.1affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-19986

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Adblock for Youtube Extension Event Listener contentscript.js updateDynamicRules improper authorization
Source: CVE Program / CVE List V5
Vulnerability Description
A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the file contentscript.js of the component Event Listener. This manipulation of the argument yt-anti-adblock-detected causes improper authorization. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不恰当
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
-Adblock for Youtube Extension 7.2.0 cpe:2.3:a:adblock_for_youtube_extension:adblock_for_youtube_extension:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-19986

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-19986

登录查看更多情报信息。

Security Blog Posts for CVE-2026-19986 (1)

Same Patch Batch · n/a · 2026-08-17 · 15 CVEs total

CVE-2026-199653.7 LOWautomad Password Reset Endpoint UserController.php requestPasswordResetToken response disc
CVE-2026-51346StudIP 6.0.3前/5.4.12前SQL注入漏洞
CVE-2026-50769Brainformatik CRM+ <2025.6 SQL注入漏洞
CVE-2026-50771Squirro Cognitive Search <3.14.2 存储型XSS漏洞
CVE-2026-50768ImageMaster 9.14.2.8.1文件上传漏洞可致远程代码执行
CVE-2026-50770Squirro Cognitive Search <3.14.2 提权漏洞
CVE-2026-50772Squirro <3.14.2 密码重置远程代码执行漏洞
CVE-2026-50775DataHub 1.5.0.1盲注SSRF漏洞
CVE-2026-50776Pronis Loisirs Billetterie CSE目录遍历漏洞
CVE-2026-50773CGM ISIS MED 2510.1.0.20远程代码执行漏洞
CVE-2026-50774GAPTEQ Designer v3.5公司经理角色权限提升漏洞
CVE-2026-67678DocSys v2.02.80任意代码执行漏洞
CVE-2026-68004SRS <5.0.213远程代码执行漏洞
CVE-2026-68005mini_httpd <1.30拒绝服务漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-19986

No comments yet


Leave a comment