Stored OS Command Injection Vulnerability in AVideo CloneSite Plugin
CVE-2026-92580

8.7HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-92580?

The CloneSite plugin for AVideo versions up to 29.0 is vulnerable to stored OS command injection, specifically via SSH passwords. This vulnerability arises due to improper handling of user input when substituting the stored SSH password into command strings without escaping. An unauthenticated remote attacker can exploit this flaw by enticing an authenticated administrator to submit malicious data, which may include a harmful password or attacker-controlled CloneSite URL. If successful, the anomaly allows the execution of arbitrary shell commands without any additional administrative action, particularly affecting systems where the documented crontab entry is enabled. Exploitation can occur through various channels that bypass Cross-Site Request Forgery (CSRF) protections, potentially leading to severe security breaches.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

OryamDeune
.