PatchSiren cyber security CVE debrief
CVE-2026-39367 WWBN CVE debrief
AVideo's EPG feature is vulnerable to stored cross-site scripting (XSS) attacks. An attacker with upload permission can set a video's epg_link to a malicious XML file containing JavaScript payloads in <title> elements, which execute in the browser of unauthenticated visitors to the public EPG page. This vulnerability affects users of AVideo version 26.0 and prior, especially those with upload permissions. The vulnerability allows for session hijacking and account takeover. The CVSS score for this vulnerability is 5.4, indicating a medium severity.
- Vendor
- WWBN
- Product
- AVideo
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-07-24
Who should care
Users of AVideo version 26.0 and prior, especially those with upload permissions, should be aware of this vulnerability and take immediate action to mitigate the risk. This includes updating AVideo to a version beyond 26.0, validating and sanitizing all user-controlled input to the EPG feature, and implementing Content Security Policy (CSP) to restrict JavaScript execution. Additionally, monitoring for suspicious activity on the EPG page and considering temporary disabling of the EPG feature until a patch is applied are recommended.
Technical summary
The AVideo EPG feature improperly handles XML parsing from user-controlled URLs, leading to a stored XSS vulnerability. An attacker can inject malicious JavaScript code into <title> elements of XML files, which are then executed in the browsers of visitors to the public EPG page. This allows for session hijacking and account takeover. The vulnerability is particularly concerning for users with upload permissions in AVideo version 26.0 and prior.
Defensive priority
Medium priority due to the CVSS score of 5.4 and the potential for session hijacking and account takeover.
Recommended defensive actions
- Update AVideo to a version beyond 26.0
- Validate and sanitize all user-controlled input to the EPG feature
- Implement Content Security Policy (CSP) to restrict JavaScript execution
- Monitor for suspicious activity on the EPG page
- Consider temporarily disabling the EPG feature until a patch is applied
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-04-07T20:16:30.677Z and last modified on 2026-07-24T21:10:00.143Z. The NVD entry is currently Analyzed. This information is based on the provided source corpus. Defenders should verify the accuracy of this information within the limits of publicly available data. Additional verification tasks may be necessary to confirm affected scope and severity.
Official resources
-
CVE-2026-39367 CVE record
CVE.org
-
CVE-2026-39367 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch
-
Mitigation or vendor reference
[email protected] - Third Party Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T20:16:30.677Z and has not been modified since then. The NVD entry is currently Analyzed.