Authentication Bypass in WWBN AVideo Video Platform
CVE-2026-43873
7.5HIGH
What is CVE-2026-43873?
The WWBN AVideo platform contains a security flaw where the local CloneSite shared secret is inadvertently echoed in the HTTP response for unauthenticated requests. This oversight, present in versions up to and including 29.0, can allow attackers to access sensitive authentication credentials. When the CloneSite is set up with a remote URL, the leaked credential can be exploited by attackers to impersonate victims, potentially enabling them to execute a mysqldump of the remote server's database, leading to unauthorized access to all public videos and clones. The issue has been addressed with an updated fix in a recent commit.
Affected Version(s)
AVideo <= 29.0
