Open Source Video Platform Vulnerability Affecting WWBN AVideo
CVE-2026-35449

5.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-35449?

WWBN AVideo, an open-source video platform, has a vulnerability in its diagnostic script install/test.php. This script inadvertently allows unauthorized access via HTTP, exposing sensitive data such as video viewer statistics, IP addresses, session IDs, and user agents to anyone without authentication. The issue arises from the removal of the guard against CLI access, enabling exposure of critical user data following installation. Users of AVideo versions 26.0 and earlier are particularly at risk and should address this vulnerability promptly.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.