Unauthenticated File Read Vulnerability in WWBN AVideo Product
CVE-2026-89250
8.7HIGH
What is CVE-2026-89250?
An unauthenticated file read vulnerability exists in the WWBN AVideo software, specifically in the getRecordedFile.php endpoint. This flaw allows unauthorized attackers to request recorded live video files stored in the temporary directory by simply knowing or guessing the stream key. Since there are no authentication or authorization checks in place, this may lead to exposure of sensitive video content, thereby compromising user privacy and data integrity. It is crucial for users of AVideo to apply the latest updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
AVideo 0
