CVE-2026-35449

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after installation, exposing video viewer statistics including IP addresses, session IDs, and user agents to unauthenticated visitors.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*

History

23 Apr 2026, 15:31

Type Values Removed Values Added
CPE cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
First Time Wwbn
Wwbn avideo
References () https://github.com/WWBN/AVideo/security/advisories/GHSA-hg8q-8wqr-35xx - () https://github.com/WWBN/AVideo/security/advisories/GHSA-hg8q-8wqr-35xx - Exploit, Mitigation, Vendor Advisory

07 Apr 2026, 14:16

Type Values Removed Values Added
References () https://github.com/WWBN/AVideo/security/advisories/GHSA-hg8q-8wqr-35xx - () https://github.com/WWBN/AVideo/security/advisories/GHSA-hg8q-8wqr-35xx -

06 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-06 22:16

Updated : 2026-04-23 15:31


NVD link : CVE-2026-35449

Mitre link : CVE-2026-35449

CVE.ORG link : CVE-2026-35449


JSON object : View

Products Affected

wwbn

  • avideo
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor