CVE-2026-43885

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints (e.g. users_list) without logging in. Commit 1c36f229d0a103528fb9f64d0a1cc0e1e8f5999b contains an updated fix.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-05-11 22:22

Updated : 2026-06-17 10:50


NVD link : CVE-2026-43885

Mitre link : CVE-2026-43885

CVE.ORG link : CVE-2026-43885


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-862

Missing Authorization