Unauthenticated API Access Vulnerability in WWBN AVideo Platform
CVE-2026-43885

7.7HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-43885?

WWBN AVideo, an open-source video platform, has a vulnerability that allows unauthenticated users to access sensitive information. Specifically, users can read the APISecret from the objects/plugins.json.php file, which can then be exploited to interact with protected API endpoints such as users_list without the need for authentication. The issue has been addressed in an update, ensuring that security measures are in place to protect user data from unauthorized access.

Affected Version(s)

AVideo <= 29.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.