CVE-2026-43873Disclosure

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.php echoes the local CloneSite shared secret ($objClone->myKey, a constant md5($global['systemRootPath'] . $global['salt'])) into the HTTP response body on every unauthenticated request. The unauthenticated error branch was intended to reject non-admin callers without a valid key, but the rejection message interpolates the expected key before die(). When the victim has CloneSite configured with a remote cloneSiteURL (standard federation/backup setup), the leaked myKey is exactly the credential that authenticates the victim to that remote server's cloneServer.json.php, allowing the attacker to impersonate the victim and trigger a full mysqldump of the remote's database to the remote's public videos/clones/ directory Commit e6566f56a28f4556b2a0a09d03717a719dcb49da contains an updated fix.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-209

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-05-11); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-11: 2Mentions · 2026-05-12: 1Patch / Workaround · 2026-05-11: 1Technical Details · 2026-05-11: 2Technical Details · 2026-05-12: 105-1105-12
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-112
Disclosure1Patch1
2026-05-121
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-43873 Unauthenticated CloneSite Secret Disclosure in WWBN AVideo Up to 29.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-43873

    Post summary

    The post announces CVE‑2026‑43873, an unauthenticated secret disclosure in WWBN AVideo versions up to 29.0, linking to a vulnerability details page but providing no PoC, exploit, or patch information.

    0000059
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    ⚠️ HIGH — CVE-2026-43873 WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.p… CVSS 7.5 Full analysis → https://sec.kaitan.id/cves/CVE-2026-43873 #HP #CyberSecurity #InfoSec

    Post summary

    A high‑severity vulnerability (CVSS 7.5) has been disclosed for WWBN AVideo, affecting the cloneClient.json component; no PoC, exploitation evidence, or patch information is provided.

    0000046
    90 followersView on X
  • Entity@0x2ed3bb60
    Patch

    CVE-2026-43873: WWBN AVideo ≤29.0 leaks CloneSite shared secret in unauthenticated error messages. Attacker obtains myKey, impersonates victim, triggers mysqldump to public directory. Fix in commit e6566f5. https://0x2ed3bb60.xyz/threat/5703656e19e54f75

    Post summary

    The alert reports a data‑leak vulnerability in WWBN AVideo that allows unauthenticated disclosure of a CloneSite secret and a potential mysqldump to a public directory, and it provides a fix via a specific commit.

    0000049
    7 followersView on X

Explore more