CVE-2026-29058Disclosure(wwbn / avideo-encoder)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wwbn avideo-encoder systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter. This can lead to full server compromise, data exfiltration (e.g., configuration secrets, internal keys, credentials), and service disruption. This issue has been patched in version 7.0.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo-encoder

Threat summary

  • Patch or workaround signal is available
  • 13 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 11 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 6 mentions (2026-03-06); latest day: 1
  • 13 total mentions across 8 days

Affected systems

Vendors
Products
avideo-encoder

Deep dive

Activity timeline13 mentions / 8d
02356Mentions · 2026-03-05: 1Mentions · 2026-03-06: 6Mentions · 2026-03-09: 1Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Mentions · 2026-03-23: 1Mentions · 2026-04-16: 1Mentions · 2026-10-05: 1Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-06: 2Patch / Workaround · 2026-03-09: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 5Technical Details · 2026-03-09: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-23: 1Technical Details · 2026-04-16: 103-0503-0603-0903-1103-1303-2304-1610-05
Signal classification3 categories
Disclosure
758.3%
Patch
433.3%
General
18.3%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-051
Patch1
2026-03-066
Disclosure3General1Patch2
2026-03-091
Patch1
2026-03-111
Disclosure1
2026-03-131
Disclosure1
2026-03-231
Disclosure1
2026-04-161
Disclosure1
Full discourse13 posts
  • pdnuclei-bot@pdnuclei_bot

    🚨 CVE-2026-29058 - critical 🚨 WWBN AVideo Encoder < 7.0 - Unauthenticated OS Command Injection > AVideo < 7.0 contains a command injection caused by shell command substitution in the... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-29058 @pdnuclei #NucleiTemplates #cve

    00022307
    1.3K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    A critical 9.8 CVSS flaw (CVE-2026-29058) in AVideo-Encoder allows unauthenticated remote attackers to execute arbitrary system commands. Patch now. #AVideoEncoder #CVE202629058 #CyberSecurity #InfoSec #RCE #Vulnerability #PatchAlert #CommandInjection https://securityonline.info/stream-hijacked-critical-zero-click-command-injection-flaw-exposed-in-avideo-encoder/

    Post summary

    The tweet announces a critical CVE-2026-29058 flaw in AVideo‑Encoder that allows remote command execution and urges immediate patching.

    11011501
    10.6K followersView on X
  • Divert@Divert_Security
    Disclosure

    CVE-2026-29058, AVideo command injection was disclosed 3/6/2026. We caught probes earlier, on 2/21/2026. https://t.co/Xti6syxtUJ

    Post summary

    The tweet announces the disclosure of CVE-2026-29058, describing an AVideo command injection vulnerability and noting that probes were detected, without revealing PoC, exploit code, or patch details.

    0001025
    7 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    AVideo プラットフォームの脆弱性 CVE-2026-29058 が FIX:OS コマンド・インジェクションの恐れ https://iototsecnews.jp/2026/03/06/avideo-platform-vulnerability-allows-hackers-to-hijack-streams-via-zero-click-command-injection/ 動画配信プラットフォーム AVideo で発見された、深刻な脆弱性 CVE-2026-29058 (CVSS 9.8) は、サーバの完全な乗っ取りを許す可能性のある、きわめて危険なものです。この問題の原因は、画像処理コンポーネントにおいて、ユーザーが入力したパラメータが無害化されずに、OS の実行コマンドへ直接組み込まれたことにあります。したがって、攻撃者は細工したリクエストを送るだけで、ログイン不要かつユーザーの操作なしに、サーバ上で任意のプログラムをゼロクリック実行できる状況にあります。それにより、機密データの窃取やシステムの破壊が可能となります。ご利用のチームは、ご注意ください。 #AVideo #CVE202629058 #Vulnerability

    Post summary

    The article reports the discovery of CVE‑2026‑29058, an OS command injection flaw in AVideo that allows attackers to fully compromise servers with a single crafted request, but offers no evidence of exploitation or mitigation steps.

    01000138
    484 followersView on X
  • Hackviser@hackviserr
    Disclosure

    Ready to exploit an unauthenticated command injection and pop a shell on a video encoding server?⚡️🚨 Just added to Hackviser Labs: AVideo Encoder getImage.php Command Injection (CVE-2026-29058)🔥 This critical unauthenticated vulnerability lets attackers gain remote code execution on AVideo Encoder 6.0 — and we've already got the environment ready for you to exploit! Perfect for security professionals and enthusiasts looking to understand and practice with real-world vulnerabilities. How would you approach initial enumeration before attempting exploitation? Drop your first step in the comments 👇

    Post summary

    The post announces a new CVE (2026-29058) exposing unauthenticated command injection and remote code execution in AVideo Encoder, emphasizing that an environment is prepared for exploitation.

    00000260
    4.3K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-29058 (CVSS:9.8, CRITICAL) is Analyzed. AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS ..https://nvd.nist.gov/vuln/detail/CVE-2026-29058 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    Announces a critical CVE (CVE-2026-29058) affecting AVideo before version 7.0, noting an unauthenticated exploit that allows arbitrary OS command execution.

    0000042
    172 followersView on X
  • StrongKeep Cybersecurity@StrongKeepCyber
    Patch

    Smart SMBs, beware: AVideo’s zero-click command injection could let an attacker hijack streams without any clicks. Stay calm, stay patched — monitor CVE-2026-29058 and apply updates as soon as they’re released. Read more: https://cybersecuritynews.com/avideo-platform-vulnerability/

    Post summary

    The post warns SMBs of a zero‑click command injection in AVideo (CVE‑2026‑29058) and urges immediate patching to mitigate the risk.

    0000053
    2 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29058 AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell comm… https://www.cve.org/CVERecord?id=CVE-2026-29058

    Post summary

    CVE-2026-29058 discloses that pre‑7.0 versions of AVideo allow unauthenticated attackers to execute arbitrary OS commands through shell command injection.

    00000143
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29058 Unauthenticated Remote Code Execution in AVideo Platform Versions Prior to 7.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29058

    Post summary

    The text announces a new unauthenticated remote code execution vulnerability in AVideo Platform versions prior to 7.0, providing the CVE identifier and a link to a generic vulnerability details page.

    0000039
    4.0K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    General

    🚨 #CVE-2026-29058: The Zero-Click AVideo Hack That Lets Attackers Run Wild on Your Streaming Servers + Video https://undercodetesting.com/cve-2026-29058-the-zero-click-avideo-hack-that-lets-attackers-run-wild-on-your-streaming-servers-video/ Educational Purposes!

    Post summary

    The post references CVE‑2026‑29058 via a link but provides no explicit PoC, exploit details, patch, or confirmation of active exploitation.

    0000039
    403 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-29058 - Critical AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into... https://www.thehackerwire.com/vulnerability/CVE-2026-29058/ https://t.co/P3Cc0oHoFS

    Post summary

    The post announces CVE‑2026‑29058 as a critical flaw that lets unauthenticated attackers run arbitrary OS commands on AVideo servers prior to v7.0, but provides no PoC, patch, or evidence of active exploitation.

    0000045
    125 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-29058: CRITICAL] Critical security vulnerability in AVideo platform (pre-v7.0)! Unauthenticated attackers could execute OS commands via shell command injection. Update to version 7.0 to fix.#cve,CVE-2026-29058,#cybersecurity https://cvefind.com/CVE-2026-29058

    Post summary

    A new critical shell command injection vulnerability (CVE‑2026‑29058) affects V7.0‑pre versions of the AVideo platform, and a security advisory recommends upgrading to version 7.0 to mitigate it.

    0000097
    597 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    `WWBN AVideo` is vulnerable to unauthenticated OS Command Injection (CVE-2026-29058) via `base64Url` in `objects/getImage.php`. Update to `7.0.0` to mitigate `RCE` risk. #AVideo #InfoSec #CVE https://www.pulsepatch.io/posts/cve-2026-29058-wwbn-avideo-os-command-injection

    Post summary

    The post announces an unauthenticated OS Command Injection vulnerability in WWBN AVideo and recommends upgrading to version 7.0.0 to mitigate the RCE risk, but provides no proof of concept, exploit code, or evidence of active exploitation.

    0000039
    1 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo-encoder---

Explore more