Junglewise Threat Intelligence

CVE-2026-43885: WWBN AVideo information disclosure in plugins.json.php

CVE-2026-43885 · Severity: high · CVSS 4 · Published 2026-05-11

Technologies: wwbn/avideo (Packagist), WWBN AVideo. Vendors: Packagist, WWBN.

Executive brief

WWBN AVideo is an open-source video sharing and streaming platform. A security flaw allows unauthenticated visitors to access sensitive configuration files that contain the system's API secret key. An attacker can use this stolen key to gain unauthorized access to protected administrative data, such as user lists, potentially compromising the privacy and security of the entire platform.

Technical details

A sensitive information disclosure vulnerability exists in WWBN AVideo due to improper authorization checks in the 'objects/plugins.json.php' endpoint. This endpoint is publicly accessible and fails to redact the 'APISecret' stored within the 'object_data' field for unauthenticated requests. An attacker can retrieve this secret and use it as a valid authentication token for the 'plugin/API/get.json.php' endpoint. This allows the attacker to execute protected API calls, such as 'users_list', effectively bypassing authentication. A fix has been introduced in commit 1c36f229d0a103528fb9f64d0a1cc0e1e8f5999b.

Affected products

  • WWBN AVideo <= 29.0

Timeline

  • 2026-04-27: advisory: GitHub Security Advisory published
  • 2026-05-11: disclosed: CVE published to NVD

References

Related threats