Vulnerability Description
WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints (e.g. users_list) without logging in. Commit 1c36f229d0a103528fb9f64d0a1cc0e1e8f5999b contains an updated fix.
Related Weaknesses (CWE)
References
- https://github.com/WWBN/AVideo/commit/1c36f229d0a103528fb9f64d0a1cc0e1e8f5999b
- https://github.com/WWBN/AVideo/security/advisories/GHSA-xr49-f4rh-qcjf
- https://github.com/WWBN/AVideo/security/advisories/GHSA-xr49-f4rh-qcjf
FAQ
What is CVE-2026-43885?
CVE-2026-43885 is a documented vulnerability. WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints ...
How severe is CVE-2026-43885?
CVSS scoring is not yet available for CVE-2026-43885. Check NVD for updates.
Is there a patch for CVE-2026-43885?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.