PT-2026-27192 · Avideo · Cdn Plugin+1
Restriction
·
Published
2026-03-23
·
Updated
2026-03-26
·
CVE-2026-33719
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
AVideo versions up to and including 26.0
Description
AVideo is an open source video platform. The CDN plugin endpoints
plugin/CDN/status.json.php and plugin/CDN/disable.json.php use key-based authentication with an empty string as the default key. When the CDN plugin is enabled and the key is not configured, the key validation check is bypassed. This allows unauthenticated attackers to modify the full CDN configuration, including CDN URLs, storage credentials, and the authentication key itself, via mass-assignment through the par request parameter.Recommendations
Update to a version after 26.0.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Avideo
Cdn Plugin