CVE-2026-56345Disclosure

LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

0.0/ 10 priority

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-06-20); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-20: 3Mentions · 2026-06-21: 1Technical Details · 2026-06-20: 3Technical Details · 2026-06-21: 106-2006-21
Signal classification1 categories
Disclosure
4100.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-06-203
Disclosure3
2026-06-211
Disclosure1
Full discourse4 posts
  • CVE Official@CVE2026COIN
    Disclosure

    🟠 HIGH (CVSS 8.1) — CVE-2026-56345 Published: 2026-06-20 AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verification. An attacker with knowledge of the Meet shared secret can craft a malicious file upload with a filename containing an arbitrary users_id to invoke passwordless User->login() and establish an authenticated session as any user including admin. Attackers can obtain the Meet shared secret through path-traversal vulnerabilities or timing attacks against checkToken.json.php, then POST a crafted file to uploadRecordedVideo.json.php with a filename like '1-anything.mp4' to hijack admin sessions and gain full account takeover. 🧬 CVSS 3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H 🔗 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-56345 📚 References: • https://github.com/WWBN/AVideo/security/advisories/GHSA-qxvm-r42f-5p8j • https://www.vulncheck.com/advisories/avideo-arbitrary-user-session-hijacking-via-meet-plugin-uploadrecordedvideo-endpoint #CVE #CyberSecurity #InfoSec #Vulnerability

    Post summary

    The post announces the disclosure of CVE‑2026‑56345, an authorization bypass in AVideo's Meet plugin, detailing how attackers can hijack admin sessions via crafted file uploads and secret extraction.

    1001053
    21 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-56345 AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from th… https://www.cve.org/CVERecord?id=CVE-2026-56345 ----- Traducción: CVE-2026-56345 AVi… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-56345, detailing an authorization bypass vulnerability in AVideo’s Meet plugin, and references the official CVE record without providing PoC, exploit, or patch information.

    0000031
    88 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-56345 Authorization Bypass in AVideo Meet Plugin uploadRecordedVideo.js... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-56345 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A tweet announcing CVE‑2026‑56345, describing an Authorization Bypass in the AVideo Meet Plugin's uploadRecordedVideo.js, and linking to a vulnerability details page.

    0000043
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-56345 AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from th… https://www.cve.org/CVERecord?id=CVE-2026-56345

    Post summary

    The text discloses CVE‑2026‑56345 as an authorization bypass flaw in AVideo's Meet plugin, detailing the affected endpoint and the nature of the vulnerability, but provides no evidence of exploitation or remediation.

    00000318
    57.7K followersView on X

Explore more