Open Source Video Platform Vulnerability Affecting WWBN AVideo
CVE-2026-35449
5.3MEDIUM
What is CVE-2026-35449?
WWBN AVideo, an open-source video platform, has a vulnerability in its diagnostic script install/test.php. This script inadvertently allows unauthorized access via HTTP, exposing sensitive data such as video viewer statistics, IP addresses, session IDs, and user agents to anyone without authentication. The issue arises from the removal of the guard against CLI access, enabling exposure of critical user data following installation. Users of AVideo versions 26.0 and earlier are particularly at risk and should address this vulnerability promptly.
Affected Version(s)
AVideo <= 26.0
