Critical severity9.8NVD Advisory· Published Sep 5, 2026
CVE-2026-86189
CVE-2026-86189
Description
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the application root and subdirectories.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.