PT-2026-27192 · Avideo · Cdn Plugin+1

Restriction

·

Publicado

2026-03-23

·

Atualizado

2026-03-26

·

CVE-2026-33719

CVSS v3.1

8.6

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions AVideo versions up to and including 26.0
Description AVideo is an open source video platform. The CDN plugin endpoints plugin/CDN/status.json.php and plugin/CDN/disable.json.php use key-based authentication with an empty string as the default key. When the CDN plugin is enabled and the key is not configured, the key validation check is bypassed. This allows unauthenticated attackers to modify the full CDN configuration, including CDN URLs, storage credentials, and the authentication key itself, via mass-assignment through the par request parameter.
Recommendations Update to a version after 26.0.

Exploit

Correção

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-33719
GHSA-R64R-883R-WCWH

Produtos afetados

Avideo
Cdn Plugin