PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-82647 WWBN CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T15:16:45.160Z and has not been modified since then. The AVideo application contains a cross-site request forgery vulnerability in sendEmail.json.php. This vulnerability allows attackers to craft malicious web pages that, when visited by authenticated administrators, can send emails with attacker-controlled subject and body to arbitrary recipients, bypassing origin checks and captcha validation. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM. AVideo administrators and users, security teams monitoring for potential phishing and brand impersonation attacks, and organizations using AVideo for email communication should be aware of this vulnerability and take steps to mitigate it. This includes verifying administrator accounts for potential compromise, implementing compensating controls, and educating administrators on safe browsing practices. Additionally, security teams should monitor for suspicious email activity and review compensating controls for exposed systems while remediation is scheduled and verified. AVideo installations should be inventoried and verified for potential compromise, and access to AVideo's sendEmail.json.php functionality should be restricted. Administrators should be educated on safe browsing practices to prevent phishing and brand impersonation attacks. Security teams should also track exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability can be mitigated by applying vendor remediation when available, restricting access to AVideo's sendEmail.json.php functionality, and educating administrators on safe browsing practices. Compensating controls such as monitoring for suspicious email activity should be implemented. Asset inventory and rollback/change windows should be reviewed to ensure that exposed systems are properly managed. Source tracking and exposure review should also be conducted to ensure that the vulnerability is properly understood and mitigated.

Vendor
WWBN
Product
AVideo
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-30
Original CVE updated
2026-08-30
Advisory published
2026-08-30
Advisory updated
2026-08-30

Who should care

AVideo administrators and users, security teams monitoring for potential phishing and brand impersonation attacks, and organizations using AVideo for email communication should be aware of this vulnerability and take steps to mitigate it. This includes verifying administrator accounts for potential compromise, implementing compensating controls, and educating administrators on safe browsing practices. Additionally, security teams should monitor for suspicious email activity and review compensating controls for exposed systems while remediation is scheduled and verified. AVideo installations should be inventoried and verified for potential compromise, and access to AVideo's sendEmail.json.php functionality should be restricted. Administrators should be educated on safe browsing practices to prevent phishing and brand impersonation attacks. Security teams should also track exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability can be mitigated by applying vendor remediation when available, restricting access to AVideo's sendEmail.json.php functionality, and educating administrators on safe browsing practices. Compensating controls such as monitoring for suspicious email activity should be implemented. Asset inventory and rollback/change windows should be reviewed to ensure that exposed systems are properly managed. Source tracking and exposure review should also be conducted to ensure that the vulnerability is properly understood and mitigated. The CVE record was published on 2026-08-30T15:16:45.160Z and has not been modified since then. The vulnerability allows attackers to craft malicious web pages that send emails with controlled subject and body to arbitrary recipients when visited by authenticated admins, bypassing origin checks and captcha validation. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM. The AVideo application contains a cross-site request forgery vulnerability in sendEmail.json.php. This vulnerability allows attackers to craft malicious web pages that, when visited by authenticated administrators, can send emails with attacker-controlled subject and body to arbitra

Technical summary

The AVideo application contains a cross-site request forgery vulnerability in sendEmail.json.php. This vulnerability allows attackers to craft malicious web pages that, when visited by authenticated administrators, can send emails with attacker-controlled subject and body to arbitrary recipients, bypassing origin checks and captcha validation. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM.

Defensive priority

Authenticated administrators are at risk of being phished or used for brand impersonation attacks when visiting malicious web pages.

Recommended defensive actions

  • Inventory AVideo installations and verify administrator accounts for potential compromise.
  • Implement compensating controls such as monitoring for suspicious email activity.
  • Apply vendor remediation when available.
  • Restrict access to AVideo's sendEmail.json.php functionality.
  • Educate administrators on safe browsing practices.

Evidence notes

The CVE-2026-82647 vulnerability allows attackers to craft malicious web pages that send emails with controlled subject and body to arbitrary recipients when visited by authenticated admins, bypassing origin checks and captcha validation. Evidence is limited to source-provided details and may not reflect the full scope or impact of the vulnerability. Defenders should verify AVideo installations, monitor for suspicious email activity, and educate administrators on safe browsing practices.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-82647 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-82647

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-82647 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82647

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.