Unauthenticated Arbitrary File Write in AVideo by WWBN
CVE-2026-72748

6.9MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72748?

AVideo has a vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to exploit an unauthenticated arbitrary file write. By sending HTTP PUT requests, malicious entities can write up to 4 GB of arbitrary content to the server's filesystem. This can lead to denial of service by exhausting disk space, disrupt the video encoding process, or potentially be combined with local file inclusion to enable remote code execution.

Affected Version(s)

AVideo 29.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DhiyaneshGeek
neo-ai-engineer
.