VYPR
Medium severity5.3NVD Advisory· Published Sep 11, 2026· Updated Sep 11, 2026

CVE-2026-89248

CVE-2026-89248

Description

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebRTC/status.json.php and receive JSON containing the absolute filesystem path of the WebRTC2RTMP helper binary (revealing the document-root path), the configured WebRTC port, file_exists/is_executable status for the binary, the contents of the WebRTC log/JSON files (videos/WebRTC2RTMP.log) when present, and whether the configured port is reachable on loopback (127.0.0.1) and on the public address. The endpoint performs no User::isLogged(), User::isAdmin(), or forbiddenPage() check. The issue was unfixed at the time of reporting.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • WWBN/Avideoinferred
    Range: <=commit c3edcc274c389816d434acadac07ee78eaf330c1
  • AVideo/AVideollm-fuzzy
    Range: before commit c3edcc274c389816d434acadac07ee78eaf330c1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.