Unauthenticated Remote File Access in WWBN AVideo
CVE-2026-46337

6.9MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
29 May 2026

What is CVE-2026-46337?

WWBN AVideo, an open-source video platform, contains a vulnerability that allows unauthenticated remote attackers to read arbitrary image files stored on disk. This includes sensitive files such as private user-profile photos, admin-uploaded thumbnails, and encrypted video poster frames. The vulnerability is due to inadequate access control, permitting the exploitation of directory traversal techniques to access files that should otherwise be restricted. Version 29.0 and earlier are susceptible, making it crucial for users to take preventive measures to secure their installations.

Affected Version(s)

AVideo <= 29.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.