WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the application root and subdirectories.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-05 13:18
Updated : 2026-09-08 20:05
NVD link : CVE-2026-86189
Mitre link : CVE-2026-86189
CVE.ORG link : CVE-2026-86189
JSON object : View
Products Affected
No product.
CWE
CWE-73
External Control of File Name or Path
