Authentication Bypass Vulnerability in WWBN AVideo Open Source Video Platform
CVE-2026-34732

5.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34732?

The AVideo open source video platform suffers from a significant authentication bypass vulnerability due to the CreatePlugin template's list.json.php component lacking necessary authentication and authorization checks. This oversight exposes 21 unauthenticated data listing endpoints, potentially compromising sensitive information such as personally identifiable information (PII), payment transaction logs, IP addresses, user agents, and internal system records. Since there are no currently available patches, users are advised to take immediate measures to mitigate potential risks.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.