CSRF Vulnerability in AVideo by WWBN
CVE-2026-34394

8.1HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34394?

AVideo, an open-source video platform, is susceptible to serious security concerns due to a lack of CSRF token validation in its admin plugin configuration endpoint. In versions 26.0 and earlier, the system does not perform essential checks before processing administrative requests, which could allow attackers to execute forged cross-origin POST requests. This vulnerability, combined with an explicit SameSite=None cookie policy, potentially enables malicious actors to alter arbitrary settings within the platform. Furthermore, due to the bypassing of standard table-level access controls, attackers can gain complete control over critical functionalities, including payment processing and authentication configurations. Currently, there are no publicly issued patches to address this flaw.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.