Unauthenticated File Read Vulnerability in WWBN AVideo Product
CVE-2026-89250

8.7HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
11 September 2026

What is CVE-2026-89250?

An unauthenticated file read vulnerability exists in the WWBN AVideo software, specifically in the getRecordedFile.php endpoint. This flaw allows unauthorized attackers to request recorded live video files stored in the temporary directory by simply knowing or guessing the stream key. Since there are no authentication or authorization checks in place, this may lead to exposure of sensitive video content, thereby compromising user privacy and data integrity. It is crucial for users of AVideo to apply the latest updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

AVideo 0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.