PatchSiren cyber security CVE debrief
CVE-2026-35450 WWBN CVE debrief
The WWBN AVideo plugin/API/check.ffmpeg.json.php endpoint allows unauthenticated probing of FFmpeg remote server configuration. This issue affects AVideo versions 26.0 and prior. The vulnerability allows an attacker to determine the connectivity status of the FFmpeg server without providing any authentication credentials. This could potentially lead to information disclosure and further exploitation. Administrators of AVideo installations should assess and mitigate this vulnerability as it poses a medium severity risk.
- Vendor
- WWBN
- Product
- AVideo
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-06
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-06
- Advisory updated
- 2026-07-24
Who should care
Administrators of AVideo installations should assess and mitigate this vulnerability. This includes reviewing the current version of AVideo, determining if it is vulnerable, and applying patches or mitigations as necessary. Additionally, security teams and vulnerability management teams should be aware of this vulnerability and its potential impact on the organization.
Technical summary
The AVideo plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without authentication. This issue impacts AVideo versions up to 26.0. Other FFmpeg management endpoints require admin privileges. The vulnerability is a result of the lack of authentication in the endpoint, which could allow an attacker to gather information about the FFmpeg server configuration. This could potentially be used to plan further exploitation.
Defensive priority
Apply patches or mitigations to restrict access to FFmpeg management endpoints. Inventory AVideo installations for exposure and monitor for suspicious activity.
Recommended defensive actions
- Apply patches or mitigations to restrict access to FFmpeg management endpoints.
- Inventory AVideo installations for exposure.
- Monitor for suspicious activity.
- Implement compensating controls.
- Exception tracking and retest
- Review and update incident response plans to include this type of vulnerability.
- Verify that all AVideo installations are running a version that is not vulnerable.
Evidence notes
The evidence is based on CVE and NVD records. AVideo version 26.0 and prior are vulnerable. The FFmpeg endpoint requires no authentication. This issue allows unauthenticated probing of FFmpeg remote server configuration. The CVE record was published on 2026-04-06T22:16:23.463Z and has not been modified since. The information is limited, and defenders should verify the affected scope and severity with the vendor or other trusted sources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-35450 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-35450
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-35450 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-35450
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/WWBN/AVideo/security/advisories/GHSA-2vg4-rrx4-qcpq
[email protected] - Exploit, Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.