Stored Server-Side Request Forgery in WWBN AVideo Stream Log Callback
CVE-2026-39368
6.5MEDIUM
What is CVE-2026-39368?
WWBN AVideo, an open-source video platform, contains a vulnerability in its version 26.0 and earlier related to the Live restream log callback mechanism. This flaw allows an authenticated low-privilege user with streaming rights to store a potentially harmful URL. Consequently, this could lead to unauthorized server-side requests being made to internal or loopback HTTP services, exposing the system to unnecessary risks and information leaks.
Affected Version(s)
AVideo <= 26.0
