Remote Code Execution Vulnerability in WWBN AVideo Open Source Video Platform
CVE-2026-40909
8.7HIGH
What is CVE-2026-40909?
AVideo, an open-source video platform from WWBN, is affected by a vulnerability that allows unauthorized users to exploit a flaw in the locale save endpoint. The issue arises because the file path for saving locales is constructed without proper sanitization, enabling an attacker—including those who can perform a CSRF attack on an admin—to traverse directories and write arbitrary PHP files. This may lead to Remote Code Execution, posing a serious risk to systems running versions 29.0 and prior. The vulnerability has been addressed in a subsequent commit.
Affected Version(s)
AVideo <= 29.0
