Server-Side Request Forgery in WWBN AVideo Open Source Video Platform
CVE-2026-33502
9.3CRITICAL
What is CVE-2026-33502?
WWBN AVideo is an open-source video platform that has a vulnerability in its plugin/Live/test.php file. Versions up to and including 26.0 are affected by an unauthenticated server-side request forgery (SSRF), which enables remote attackers to manipulate the AVideo server into sending HTTP requests to arbitrary URLs. This vulnerability grants the potential for attackers to probe internal services and access potentially sensitive localhost resources or cloud metadata endpoints, posing significant security risks for affected installations. A patch has been released to address this issue, detailed in commit 1e6cf03e93b5a5318204b010ea28440b0d9a5ab3.
Affected Version(s)
AVideo <= 26.0
