Server-Side Request Forgery in WWBN AVideo Product
CVE-2026-85164
7.1HIGH
What is CVE-2026-85164?
A vulnerability in WWBN AVideo allows authenticated API clients to exploit the set_api_userImages endpoint, which inadequately validates profileImg and backgroundImg URLs. This vulnerability can permit attackers to feed internal URLs, thereby accessing cloud metadata or other internal services. Once fetched, the responses can be exposed at publicly accessible paths, creating potential risk for sensitive information disclosure.
Affected Version(s)
AVideo 0
