Authentication Bypass Vulnerability in WWBN AVideo Open Source Video Platform
CVE-2026-34732
5.3MEDIUM
What is CVE-2026-34732?
The AVideo open source video platform suffers from a significant authentication bypass vulnerability due to the CreatePlugin template's list.json.php component lacking necessary authentication and authorization checks. This oversight exposes 21 unauthenticated data listing endpoints, potentially compromising sensitive information such as personally identifiable information (PII), payment transaction logs, IP addresses, user agents, and internal system records. Since there are no currently available patches, users are advised to take immediate measures to mitigate potential risks.
Affected Version(s)
AVideo <= 26.0
