Unauthenticated Information Disclosure in WWBN AVideo Platform
CVE-2026-35452
5.3MEDIUM
What is CVE-2026-35452?
The WWBN AVideo platform, an open-source solution for video content management, has a vulnerability in versions up to 26.0 where the plugin/CloneSite/client.log.php endpoint allows unauthenticated access to sensitive log files. Unlike other endpoints, which require user authentication, this specific endpoint exposes critical information, such as internal filesystem paths, remote server URLs, and SSH connection metadata, potentially enabling malicious actors to exploit the system further. Users of AVideo should upgrade to a secure version to mitigate associated risks.
Affected Version(s)
AVideo <= 26.0
