CVE-2026-34369General(wwbn / avideo)

LOWCVSS 5.3 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVideo return full video playback sources (direct MP4 URLs, HLS manifests) for password-protected videos without verifying the video password. While the normal web playback flow enforces password checks via the `CustomizeUser::getModeYouTube()` hook, this enforcement is completely absent from the API code path. An unauthenticated attacker can retrieve direct playback URLs for any password-protected video by calling the API directly. Commit be344206f2f461c034ad2f1c5d8212dd8a52b8c7 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • avideo

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
avideo

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-28: 2Technical Details · 2026-03-28: 103-28
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-34369 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVideo return full v… https://www.cve.org/CVERecord?id=CVE-2026-34369

    Post summary

    The text notes that CVE-2026-34369 affects AVideo up to version 26.0 by causing the get_api_video_file and get_api_video endpoints to return full video data, but provides no further technical details, exploits, or mitigation information.

    01011227
    56.9K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-34369 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVideo return full v… https://www.cve.org/CVERecord?id=CVE-2026-34369 ----- Traducción: CVE-2026-34369 WWB… http://infoflow.cloud`

    Post summary

    The post references CVE‑2026‑34369 for WWBN AVideo, noting that certain API endpoints may expose full content, but it provides no PoC, exploit, or remediation details.

    0000046
    65 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwwbnavideo---

Explore more