Unauthenticated API Access Vulnerability in WWBN AVideo Platform
CVE-2026-43885
7.7HIGH
What is CVE-2026-43885?
WWBN AVideo, an open-source video platform, has a vulnerability that allows unauthenticated users to access sensitive information. Specifically, users can read the APISecret from the objects/plugins.json.php file, which can then be exploited to interact with protected API endpoints such as users_list without the need for authentication. The issue has been addressed in an update, ensuring that security measures are in place to protect user data from unauthorized access.
Affected Version(s)
AVideo <= 29.0
