PT-2026-29365 · Avideo · Avideo

Adrgs

·

Published

2026-03-31

·

Updated

2026-04-01

·

CVE-2026-34738

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions prior to 26.0
Description AVideo is an open source video platform. Versions 26.0 and earlier allow any uploader to set a video’s status to any valid state, including "active", through the overrideStatus request parameter. This bypasses the admin-controlled moderation and draft workflows. The setStatus() method validates the status code against a list of known values but does not verify that the caller has permission to set that particular status. As a result, any user with upload permissions can publish videos directly, circumventing content review processes. The vulnerable parameter is overrideStatus.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-34738
GHSA-M577-W9J8-CH7J

Affected Products

Avideo