CSRF Vulnerability in AVideo by WWBN
CVE-2026-34394
What is CVE-2026-34394?
AVideo, an open-source video platform, is susceptible to serious security concerns due to a lack of CSRF token validation in its admin plugin configuration endpoint. In versions 26.0 and earlier, the system does not perform essential checks before processing administrative requests, which could allow attackers to execute forged cross-origin POST requests. This vulnerability, combined with an explicit SameSite=None cookie policy, potentially enables malicious actors to alter arbitrary settings within the platform. Furthermore, due to the bypassing of standard table-level access controls, attackers can gain complete control over critical functionalities, including payment processing and authentication configurations. Currently, there are no publicly issued patches to address this flaw.
Affected Version(s)
AVideo <= 26.0
