Video Processing Bypass Vulnerability in WWBN AVideo Platform
CVE-2026-34738

4.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
31 March 2026

What is CVE-2026-34738?

The AVideo platform, known for its open-source video sharing capabilities, is subject to a security vulnerability that allows users with upload permissions to bypass content moderation processes. Specifically, in versions 26.0 and earlier, the system's video processing pipeline improperly handles the overrideStatus request parameter, enabling any uploader to set a video's status to 'active' without going through the necessary review. This flaw undermines the ability of administrators to enforce content review workflows and could lead to unauthorized content being published. Currently, there are no publicly available patches to address this issue, raising concerns for users and administrators alike.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.