PatchSiren cyber security CVE debrief
CVE-2026-39368 WWBN CVE debrief
CVE-2026-39368 is a vulnerability in WWBN AVideo versions 26.0 and prior. The Live restream log callback flow accepted an attacker-controlled restreamerURL, enabling stored SSRF for authenticated streamers. This vulnerability allows a low-privilege user with streaming permission to store an arbitrary callback URL and trigger server-side requests to loopback or internal HTTP services. The vulnerability has a CVSS score of 6.5 and a MEDIUM severity. The CVE record was published on 2026-04-07T20:16:30.877Z and has not been modified since then. To address this vulnerability, users should verify and apply vendor remediation.
- Vendor
- WWBN
- Product
- AVideo
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-07
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-07
- Advisory updated
- 2026-07-24
Who should care
Authenticated streamers and users with streaming permission on WWBN AVideo 26.0 and prior should verify and apply vendor remediation to prevent SSRF attacks. Additionally, platform administrators and security teams responsible for managing and securing video platforms should review the vulnerability and take necessary actions to protect their systems.
Technical summary
In WWBN AVideo 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restreamerURL and later fetched that stored URL server-side, enabling stored SSRF for authenticated streamers. The vulnerable flow allowed a low-privilege user with streaming permission to store an arbitrary callback URL and trigger server-side requests to loopback or internal HTTP services through the restream log feature. This vulnerability can be exploited by an attacker to perform SSRF attacks, potentially leading to unauthorized access or disruption of internal services.
Defensive priority
Medium priority due to the CVSS score of 6.5 and the potential for SSRF attacks.
Recommended defensive actions
- Verify WWBN AVideo version and apply vendor remediation if running 26.0 or prior.
- Restrict access to the restream log feature for low-privilege users.
- Monitor server-side requests to detect potential SSRF attacks.
- Implement compensating controls to prevent SSRF attacks.
- Review server logs for suspicious activity.
- Perform regular security audits to identify potential vulnerabilities.
- Consider implementing additional security measures such as IP blocking or rate limiting.
Evidence notes
The CVE record and NVD detail provide evidence of the vulnerability. The vendor has provided a mitigation or vendor reference on GitHub. To verify, defenders should review the official advisory and assess their exposure. Evidence limits suggest that additional information may be available but has not been confirmed. Affected scope and severity are based on the CVE record and NVD detail.
Official resources
-
CVE-2026-39368 CVE record
CVE.org
-
CVE-2026-39368 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Third Party Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-07T20:16:30.877Z and has not been modified since then.