Remote Configuration Exposure in WWBN AVideo Open Source Video Platform
CVE-2026-35450

5.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-35450?

The WWBN AVideo platform, a widely used open-source solution for video hosting and streaming, has a vulnerability in its API related to the ffmpeg.json.php endpoint. In versions 26.0 and earlier, this endpoint can return the connectivity status of the FFmpeg remote server configuration without requiring any form of user authentication. This weakness allows unauthorized users to probe FFmpeg remote configurations, while other management endpoints enforce necessary admin checks, enhancing the risk of unauthorized access to sensitive configurations.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.