Arbitrary Command Execution Vulnerability in WWBN AVideo Video Platform
CVE-2026-33648

8.8HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
23 March 2026

What is CVE-2026-33648?

WWBN AVideo, an open source video platform, is susceptible to an arbitrary command execution vulnerability due to improper validation of user input. Specifically, versions up to and including 26.0 fail to sanitize the users_id and liveTransmitionHistory_id parameters from the JSON request body when constructing log file paths. This vulnerability enables authenticated users to execute arbitrary commands on the server by injecting shell metacharacters, risking significant breaches in system security. The issue has been addressed in a subsequent update, where a patch has been implemented to mitigate these vulnerabilities.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.