Unauthenticated Information Disclosure in WWBN AVideo Platform
CVE-2026-35452

5.3MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
6 April 2026

What is CVE-2026-35452?

The WWBN AVideo platform, an open-source solution for video content management, has a vulnerability in versions up to 26.0 where the plugin/CloneSite/client.log.php endpoint allows unauthenticated access to sensitive log files. Unlike other endpoints, which require user authentication, this specific endpoint exposes critical information, such as internal filesystem paths, remote server URLs, and SSH connection metadata, potentially enabling malicious actors to exploit the system further. Users of AVideo should upgrade to a secure version to mitigate associated risks.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.