PT-2026-29362 · Avideo · Avideo

Adrgs

·

Published

2026-03-31

·

Updated

2026-04-01

·

CVE-2026-34732

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions 26.0 and prior
Description The AVideo platform, an open source video platform, has an issue in the CreatePlugin template for list.json.php in versions 26.0 and prior. This template lacks authentication and authorization checks. While other templates, add.json.php and delete.json.php, require admin privileges, list.json.php does not. This omission affects plugins using the CreatePlugin code generator, resulting in 21 unauthenticated data listing endpoints. These endpoints expose sensitive data including user PII, payment transaction logs, IP addresses, user agents, and internal system records.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2026-34732
GHSA-G2MG-CGR6-VMV7

Affected Products

Avideo