PatchSiren cyber security CVE debrief
CVE-2026-56345 AVideo CVE debrief
CVE-2026-56345 is a critical authorization bypass vulnerability in AVideo's Meet plugin. The vulnerability exists in the uploadRecordedVideo.json.php endpoint, which allows an attacker to derive the target user's ID from the uploaded filename without verification. This enables an attacker with knowledge of the Meet shared secret to craft a malicious file upload and establish an authenticated session as any user, including admin. The vulnerability has a CVSS score of 9.2 and is considered critical.
- Vendor
- AVideo
- Product
- Unknown
- CVSS
- CRITICAL 9.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-20
- Original CVE updated
- 2026-06-23
- Advisory published
- 2026-06-20
- Advisory updated
- 2026-06-23
Who should care
Defenders of AVideo installations, particularly those using the Meet plugin, should be aware of this vulnerability. The vulnerability allows for arbitrary user session hijacking, which can lead to full account takeover. AVideo users, administrators, and security teams should prioritize patching or mitigating this vulnerability to prevent potential attacks.
Technical summary
The vulnerability exists in the uploadRecordedVideo.json.php endpoint of the Meet plugin in AVideo. An attacker can craft a malicious file upload with a filename containing an arbitrary users_id to invoke passwordless User->login() and establish an authenticated session as any user, including admin. The Meet shared secret can be obtained through path-traversal vulnerabilities or timing attacks against checkToken.json.php. The CVSS vector for this vulnerability is CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.
Defensive priority
High priority due to critical CVSS score and potential for full account takeover
Recommended defensive actions
- Apply patches or updates to AVideo and the Meet plugin to fix the vulnerability
- Review and update the Meet shared secret to prevent unauthorized access
- Implement compensating controls, such as monitoring and logging, to detect potential attacks
- Conduct a thorough inventory of AVideo installations and assess exposure to this vulnerability
- Review official advisories and vendor-supported remediation guidance
Evidence notes
The vulnerability is described in the CVE record and NVD detail pages. The Meet shared secret can be obtained through path-traversal vulnerabilities or timing attacks against checkToken.json.php. AVideo users should verify their installations and assess exposure to this vulnerability. The vulnerability has a CVSS score of 9.2 and is considered critical.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-56345 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-56345
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-56345 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-56345
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/WWBN/AVideo/security/advisories/GHSA-qxvm-r42f-5p8j
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/avideo-arbitrary-user-session-hijacking-via-meet-plugin-uploadrecordedvideo-endpoint
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.