Stored Server-Side Request Forgery in WWBN AVideo Stream Log Callback
CVE-2026-39368

6.5MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
7 April 2026

What is CVE-2026-39368?

WWBN AVideo, an open-source video platform, contains a vulnerability in its version 26.0 and earlier related to the Live restream log callback mechanism. This flaw allows an authenticated low-privilege user with streaming rights to store a potentially harmful URL. Consequently, this could lead to unauthorized server-side requests being made to internal or loopback HTTP services, exposing the system to unnecessary risks and information leaks.

Affected Version(s)

AVideo <= 26.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.