CORS Vulnerability in WWBN AVideo Video Platform
CVE-2026-41057
7.1HIGH
What is CVE-2026-41057?
WWBN AVideo, an open source video platform, has a CORS vulnerability that affects its API endpoints in versions 29.0 and below. The flaw lies in insufficient validation of CORS origin headers, specifically in the 'plugin/API/router.php' file, which reflects arbitrary 'Origin' requests without proper validation, leading to potential unauthorized access to user data. Attackers can exploit this vulnerability by making credentialed cross-origin requests to any of the API endpoints, thereby accessing sensitive user information such as personal identifiable information (PII), email addresses, admin status, and session-related data. A fix for this issue has been implemented in a later commit.
Affected Version(s)
AVideo <= 29.0
