WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the application root and subdirectories.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sat, 05 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the application root and subdirectories. | |
| Title | WWBN AVideo Unauthenticated Path Traversal via notify.ffmpeg.json.php | |
| First Time appeared |
Wwbn
Wwbn avideo |
|
| Weaknesses | CWE-73 | |
| CPEs | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wwbn
Wwbn avideo |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-05T12:09:04.748Z
Reserved: 2026-09-05T11:51:31.101Z
Link: CVE-2026-86189
No data.
Status : Received
Published: 2026-09-05T13:18:14.000
Modified: 2026-09-05T13:18:14.000
Link: CVE-2026-86189
No data.
OpenCVE Enrichment
Updated: 2026-09-05T13:30:05Z
Weaknesses