Unauthenticated Remote File Access in WWBN AVideo
CVE-2026-46337
6.9MEDIUM
What is CVE-2026-46337?
WWBN AVideo, an open-source video platform, contains a vulnerability that allows unauthenticated remote attackers to read arbitrary image files stored on disk. This includes sensitive files such as private user-profile photos, admin-uploaded thumbnails, and encrypted video poster frames. The vulnerability is due to inadequate access control, permitting the exploitation of directory traversal techniques to access files that should otherwise be restricted. Version 29.0 and earlier are susceptible, making it crucial for users to take preventive measures to secure their installations.
Affected Version(s)
AVideo <= 29.0
