PatchSiren cyber security CVE debrief
CVE-2026-82647 WWBN CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T15:16:45.160Z and has not been modified since then. The AVideo application contains a cross-site request forgery vulnerability in sendEmail.json.php. This vulnerability allows attackers to craft malicious web pages that, when visited by authenticated administrators, can send emails with attacker-controlled subject and body to arbitrary recipients, bypassing origin checks and captcha validation. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM. AVideo administrators and users, security teams monitoring for potential phishing and brand impersonation attacks, and organizations using AVideo for email communication should be aware of this vulnerability and take steps to mitigate it. This includes verifying administrator accounts for potential compromise, implementing compensating controls, and educating administrators on safe browsing practices. Additionally, security teams should monitor for suspicious email activity and review compensating controls for exposed systems while remediation is scheduled and verified. AVideo installations should be inventoried and verified for potential compromise, and access to AVideo's sendEmail.json.php functionality should be restricted. Administrators should be educated on safe browsing practices to prevent phishing and brand impersonation attacks. Security teams should also track exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability can be mitigated by applying vendor remediation when available, restricting access to AVideo's sendEmail.json.php functionality, and educating administrators on safe browsing practices. Compensating controls such as monitoring for suspicious email activity should be implemented. Asset inventory and rollback/change windows should be reviewed to ensure that exposed systems are properly managed. Source tracking and exposure review should also be conducted to ensure that the vulnerability is properly understood and mitigated.
- Vendor
- WWBN
- Product
- AVideo
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-30
- Original CVE updated
- 2026-08-30
- Advisory published
- 2026-08-30
- Advisory updated
- 2026-08-30
Who should care
AVideo administrators and users, security teams monitoring for potential phishing and brand impersonation attacks, and organizations using AVideo for email communication should be aware of this vulnerability and take steps to mitigate it. This includes verifying administrator accounts for potential compromise, implementing compensating controls, and educating administrators on safe browsing practices. Additionally, security teams should monitor for suspicious email activity and review compensating controls for exposed systems while remediation is scheduled and verified. AVideo installations should be inventoried and verified for potential compromise, and access to AVideo's sendEmail.json.php functionality should be restricted. Administrators should be educated on safe browsing practices to prevent phishing and brand impersonation attacks. Security teams should also track exceptions, retest remediated assets, and close the item only after evidence is documented. This vulnerability can be mitigated by applying vendor remediation when available, restricting access to AVideo's sendEmail.json.php functionality, and educating administrators on safe browsing practices. Compensating controls such as monitoring for suspicious email activity should be implemented. Asset inventory and rollback/change windows should be reviewed to ensure that exposed systems are properly managed. Source tracking and exposure review should also be conducted to ensure that the vulnerability is properly understood and mitigated. The CVE record was published on 2026-08-30T15:16:45.160Z and has not been modified since then. The vulnerability allows attackers to craft malicious web pages that send emails with controlled subject and body to arbitrary recipients when visited by authenticated admins, bypassing origin checks and captcha validation. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM. The AVideo application contains a cross-site request forgery vulnerability in sendEmail.json.php. This vulnerability allows attackers to craft malicious web pages that, when visited by authenticated administrators, can send emails with attacker-controlled subject and body to arbitra
Technical summary
The AVideo application contains a cross-site request forgery vulnerability in sendEmail.json.php. This vulnerability allows attackers to craft malicious web pages that, when visited by authenticated administrators, can send emails with attacker-controlled subject and body to arbitrary recipients, bypassing origin checks and captcha validation. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM.
Defensive priority
Authenticated administrators are at risk of being phished or used for brand impersonation attacks when visiting malicious web pages.
Recommended defensive actions
- Inventory AVideo installations and verify administrator accounts for potential compromise.
- Implement compensating controls such as monitoring for suspicious email activity.
- Apply vendor remediation when available.
- Restrict access to AVideo's sendEmail.json.php functionality.
- Educate administrators on safe browsing practices.
Evidence notes
The CVE-2026-82647 vulnerability allows attackers to craft malicious web pages that send emails with controlled subject and body to arbitrary recipients when visited by authenticated admins, bypassing origin checks and captcha validation. Evidence is limited to source-provided details and may not reflect the full scope or impact of the vulnerability. Defenders should verify AVideo installations, monitor for suspicious email activity, and educate administrators on safe browsing practices.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-82647 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-82647
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-82647 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-82647
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/WWBN/AVideo/security/advisories/GHSA-7h9v-f3gg-r3mq
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/wwbn-avideo-cross-site-request-forgery-via-sendemail-json-php
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.