PatchSiren cyber security CVE debrief
CVE-2026-35450 WWBN CVE debrief
The WWBN AVideo plugin/API/check.ffmpeg.json.php endpoint allows unauthenticated probing of FFmpeg remote server configuration. This issue affects AVideo versions 26.0 and prior. The vulnerability allows an attacker to determine the connectivity status of the FFmpeg server without providing any authentication credentials. This could potentially lead to information disclosure and further exploitation. Administrators of AVideo installations should assess and mitigate this vulnerability as it poses a medium severity risk.
- Vendor
- WWBN
- Product
- AVideo
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Administrators of AVideo installations should assess and mitigate this vulnerability. This includes reviewing the current version of AVideo, determining if it is vulnerable, and applying patches or mitigations as necessary. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on the organization.
Technical summary
The AVideo plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without authentication. This issue impacts AVideo versions up to 26.0. Other FFmpeg management endpoints require admin privileges. The vulnerability is a result of the lack of authentication in the endpoint, which could allow an attacker to gather information about the FFmpeg server configuration. This could potentially be used to plan further exploitation.
Defensive priority
Apply patches or mitigations to restrict access to FFmpeg management endpoints. Inventory AVideo installations for exposure and monitor for suspicious activity.
Recommended defensive actions
- Apply patches or mitigations to restrict access to FFmpeg management endpoints.
- Inventory AVideo installations for exposure.
- Monitor for suspicious activity.
- Implement compensating controls.
- Exception tracking and retest
- Review and update incident response plans to include this type of vulnerability.
- Verify that all AVideo installations are running a version that is not vulnerable.
Evidence notes
The evidence is based on CVE and NVD records. AVideo version 26.0 and prior are vulnerable. The FFmpeg endpoint requires no authentication. This issue allows unauthenticated probing of FFmpeg remote server configuration. The CVE record was published on 2026-04-06T22:16:23.463Z and has not been modified since. The information is limited, and defenders should verify the affected scope and severity with the vendor or other trusted sources.
Official resources
-
CVE-2026-35450 CVE record
CVE.org
-
CVE-2026-35450 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Exploit, Mitigation, Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T22:16:23.463Z and has not been modified since.