PT-2026-28623 · Avideo · Avideo

·

CVE-2026-34369

·

Publicado

2026-03-27

·

Atualizado

2026-03-31

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions AVideo versions up to and including 26.0
Description AVideo is an open source video platform. The get api video file and get api video API endpoints do not verify video passwords for password-protected videos. This allows an unauthenticated attacker to retrieve direct playback URLs for any password-protected video by directly calling the API. The normal web playback flow enforces password checks via the CustomizeUser::getModeYouTube() hook, but this enforcement is absent from the API code path. The issue is addressed by commit be344206f2f461c034ad2f1c5d8212dd8a52b8c7.
Recommendations Update AVideo to a version later than 26.0.

Exploit

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-34369
GHSA-Q6JJ-R49P-94FH

Produtos afetados

Avideo