PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-35452 WWBN CVE debrief

CVE-2026-35452 is a vulnerability in the WWBN AVideo open-source video platform, specifically in versions 26.0 and prior. The plugin/CloneSite/client.log.php endpoint exposes the clone operation log file without requiring authentication. This log contains internal filesystem paths, remote server URLs, and SSH connection metadata. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM. Administrators and users of WWBN AVideo should be aware of this vulnerability and take necessary actions to mitigate it. The vulnerability could potentially lead to information disclosure, and defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Vendor
WWBN
Product
AVideo
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-06
Original CVE updated
2026-07-24
Advisory published
2026-04-06
Advisory updated
2026-07-24

Who should care

Administrators and users of WWBN AVideo, especially those using versions 26.0 and prior, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing system configurations, ensuring proper authentication mechanisms are in place, and monitoring for any suspicious activity related to the CloneSite plugin. Additionally, defenders should consider implementing a robust incident response plan to quickly respond to and contain potential security incidents related to this vulnerability.

Technical summary

The vulnerability exists in the CloneSite plugin of WWBN AVideo, where the client.log.php endpoint allows unauthenticated access to clone operation logs. This log file contains sensitive information such as internal filesystem paths, remote server URLs, and SSH connection metadata. The vulnerability is rated with a CVSS score of 5.3 and a severity of MEDIUM. To mitigate this vulnerability, defenders should patch or upgrade to a version of WWBN AVideo that is not vulnerable, restrict access to the plugin/CloneSite/client.log.php endpoint, and monitor logs for any suspicious activity.

Defensive priority

Medium priority should be given to patching or mitigating this vulnerability, as it could potentially lead to information disclosure. Defenders should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Additionally, defenders should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. The defensive priority is driven by the potential for information disclosure and the need for defenders to take proactive steps to mitigate the vulnerability and protect sensitive information. Therefore, defenders should implement additional security measures to protect sensitive information and restrict access to the plugin/CloneSite/client.log.php endpoint. This can be achieved by implementing proper authentication and authorization mechanisms, monitoring logs for suspicious activity, and performing regular security audits to identify potential vulnerabilities. By taking these steps, defenders can reduce the risk associated with this vulnerability and protect their systems from potential attacks. Furthermore, defenders should consider implementing a robust incident response plan to quickly respond to and contain potential security incidents related to this vulnerability. This plan should include procedures for identifying and isolating affected systems, containing the damage, and restoring normal operations. By having a well-defined incident response plan in place, defenders can minimize the impact of a potential security incident and reduce the risk of data breaches or other security-related issues. In addition, defenders should also consider implementing a vulnerability management program to identify, classify, and prioritize vulnerabilities based on their severity and potential impact. This program should include regular vulnerability scans, risk assessments, and remediation efforts to ensure that vulnerabilities are properly addressed and mitigated. By implementing a comprehensive and robust,

Recommended defensive actions

  • Patch or upgrade to a version of WWBN AVideo that is not vulnerable
  • Restrict access to the plugin/CloneSite/client.log.php endpoint
  • Monitor logs for any suspicious activity
  • Implement additional security measures to protect sensitive information
  • Review system configurations to ensure proper authentication mechanisms are in place
  • Perform regular security audits to identify potential vulnerabilities
  • Implement a robust incident response plan to quickly respond to and contain potential security incidents related to this vulnerability

Evidence notes

The CVE record was published on 2026-04-06T22:16:23.610Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. The evidence is limited, and defenders should verify the affected scope and severity with the vendor or other trusted sources. The CVE record does not provide detailed information on the exploitability or potential impact of the vulnerability.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-06T22:16:23.610Z and has not been modified since then. The NVD entry is currently Analyzed.