PT-2026-34203 · Avideo · Avideo

CVE-2026-41057

·

Published

2026-04-14

·

Updated

2026-04-26

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions 29.0 and earlier
Description Incomplete CORS origin validation allows an attacker to make cross-origin credentialed requests to any endpoint under '/api/*'. This occurs because two code paths reflect arbitrary Origin headers with credentials allowed: the plugin/API/router.php file reflects any origin before application code executes, and the allowOrigin(true) function, used by get.json.php and set.json.php, reflects any origin with Access-Control-Allow-Credentials: true. This can lead to the exposure of authenticated responses containing session-sensitive data, email, admin status, and user PII (Personally Identifiable Information).
Recommendations Update to the version containing commit 5e2b897ccac61eb6daca2dee4a6be3c4c2d93e13.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41057
GHSA-FF5Q-CC22-FGP4

Affected Products

Avideo