PT-2026-27192 · Avideo · Cdn Plugin+1

Restriction

·

Published

2026-03-23

·

Updated

2026-03-26

·

CVE-2026-33719

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions AVideo versions up to and including 26.0
Description AVideo is an open source video platform. The CDN plugin endpoints plugin/CDN/status.json.php and plugin/CDN/disable.json.php use key-based authentication with an empty string as the default key. When the CDN plugin is enabled and the key is not configured, the key validation check is bypassed. This allows unauthenticated attackers to modify the full CDN configuration, including CDN URLs, storage credentials, and the authentication key itself, via mass-assignment through the par request parameter.
Recommendations Update to a version after 26.0.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-33719
GHSA-R64R-883R-WCWH

Affected Products

Avideo
Cdn Plugin