CVE-2026-33648Disclosure(wwbn / avideo)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch wwbn avideo systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a log file path by embedding user-controlled `users_id` and `liveTransmitionHistory_id` values from the JSON request body without any sanitization. This log file path is then concatenated directly into shell commands passed to `exec()`, allowing an authenticated user to achieve arbitrary command execution on the server via shell metacharacters such as `$()` or backticks. Commit 99b865413172045fef6a98b5e9bfc7b24da11678 contains a patch.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-23: 3Patch / Workaround · 2026-03-23: 1Technical Details · 2026-03-23: 303-23
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33648 - AVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and `liveTransmitionHistory_id` in Restreamer Log File Path Intel Report: https://ift.tt/oTeHhQG

    Post summary

    The post discloses an OS command injection vulnerability (CVE‑2026‑33648) affecting AVideo’s Restreamer log file path, providing technical details but no PoC, exploit, or patch information.

    0000025
    289 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33648 - High WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a log file path by embedding user-controlled `users_id` and `liveTransmi... https://www.thehackerwire.com/vulnerability/CVE-2026-33648/ https://t.co/ysb5lQ4B1N

    Post summary

    The message informs about CVE‑2026‑33648, a high‑severity issue in WWBN AVideo where the restreamer endpoint embeds user‑controlled data into log file paths, potentially leading to a file‑system or command‑execution vulnerability.

    0000031
    145 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33648: HIGH] Alert: Cybersecurity Risk! In WWBN AVideo up to v26.0, unpatched systems may allow authenticated users to execute arbitrary commands via shell metacharacters. Update to Commit 99b86541...#cve,CVE-2026-33648,#cybersecurity https://cvefind.com/CVE-2026-33648

    Post summary

    The post alerts on a high‑severity vulnerability (CVE‑2026‑33648) in WWBN AVideo allowing authenticated users to run arbitrary commands via shell metacharacters and recommends updating to commit 99b86541 to fix the issue.

    0000044
    606 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more