CVE-2026-34368Disclosure(wwbn / avideo)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php` contains a Time-of-Check-Time-of-Use (TOCTOU) race condition. The method reads the sender's wallet balance, checks sufficiency in PHP, then writes the new balance — all without database transactions or row-level locking. An attacker with multiple authenticated sessions can send concurrent transfer requests that all read the same stale balance, each passing the balance check independently, resulting in only one deduction being applied while the recipient is credited multiple times. Commit 34132ad5159784bfc7ba0d7634bb5c79b769202d contains a fix.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-28)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-27: 1Mentions · 2026-03-28: 2Technical Details · 2026-03-27: 1Technical Details · 2026-03-28: 103-2703-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-03-282
Disclosure2
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-34368 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php` contains a Time… https://www.cve.org/CVERecord?id=CVE-2026-34368 ----- Traducción: CVE-2026-34368 WWB… http://infoflow.cloud`

    Post summary

    The text discloses CVE-2026-34368, a time-based vulnerability affecting the transferBalance() function of the YPTWallet plugin in AVideo versions up to 26.0, with no mention of PoC, exploitation, or patch.

    0000047
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-34368 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php` contains a Time… https://www.cve.org/CVERecord?id=CVE-2026-34368

    Post summary

    The post announces CVE-2026-34368, noting a time-related vulnerability in WWBN AVideo’s YPTWallet transferBalance() method for versions up to 26.0, without providing further technical, exploit, or patch details.

    00000181
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-34368 - AVideo Vulnerable to Wallet Balance Double-Spend via TOCTOU Race Condition in transferBalance Intel Report: https://ift.tt/Xw3UN5x

    Post summary

    A threat alert for CVE‑2026‑34368, noting an AVideo vulnerability that enables double‑spend via a TOCTOU race condition in transferBalance, with no PoC, exploit, patch, or active exploitation details provided.

    0000039
    285 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more