PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35450 WWBN CVE debrief

The WWBN AVideo plugin/API/check.ffmpeg.json.php endpoint allows unauthenticated probing of FFmpeg remote server configuration. This issue affects AVideo versions 26.0 and prior. The vulnerability allows an attacker to determine the connectivity status of the FFmpeg server without providing any authentication credentials. This could potentially lead to information disclosure and further exploitation. Administrators of AVideo installations should assess and mitigate this vulnerability as it poses a medium severity risk.

Vendor
WWBN
Product
AVideo
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-07-24
Advisory published
2026-04-06
Advisory updated
2026-07-24

Who should care

Administrators of AVideo installations should assess and mitigate this vulnerability. This includes reviewing the current version of AVideo, determining if it is vulnerable, and applying patches or mitigations as necessary. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on the organization.

Technical summary

The AVideo plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without authentication. This issue impacts AVideo versions up to 26.0. Other FFmpeg management endpoints require admin privileges. The vulnerability is a result of the lack of authentication in the endpoint, which could allow an attacker to gather information about the FFmpeg server configuration. This could potentially be used to plan further exploitation.

Defensive priority

Apply patches or mitigations to restrict access to FFmpeg management endpoints. Inventory AVideo installations for exposure and monitor for suspicious activity.

Recommended defensive actions

  • Apply patches or mitigations to restrict access to FFmpeg management endpoints.
  • Inventory AVideo installations for exposure.
  • Monitor for suspicious activity.
  • Implement compensating controls.
  • Exception tracking and retest
  • Review and update incident response plans to include this type of vulnerability.
  • Verify that all AVideo installations are running a version that is not vulnerable.

Evidence notes

The evidence is based on CVE and NVD records. AVideo version 26.0 and prior are vulnerable. The FFmpeg endpoint requires no authentication. This issue allows unauthenticated probing of FFmpeg remote server configuration. The CVE record was published on 2026-04-06T22:16:23.463Z and has not been modified since. The information is limited, and defenders should verify the affected scope and severity with the vendor or other trusted sources.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T22:16:23.463Z and has not been modified since.