Video Processing Bypass Vulnerability in WWBN AVideo Platform
CVE-2026-34738
4.3MEDIUM
What is CVE-2026-34738?
The AVideo platform, known for its open-source video sharing capabilities, is subject to a security vulnerability that allows users with upload permissions to bypass content moderation processes. Specifically, in versions 26.0 and earlier, the system's video processing pipeline improperly handles the overrideStatus request parameter, enabling any uploader to set a video's status to 'active' without going through the necessary review. This flaw undermines the ability of administrators to enforce content review workflows and could lead to unauthorized content being published. Currently, there are no publicly available patches to address this issue, raising concerns for users and administrators alike.
Affected Version(s)
AVideo <= 26.0
