CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-72748 — AVideo contains an unauthenticated arbitrary file write vulnerability in the aVi...

·Source: NIST NVD

Updated:

Executive Summary

AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achiev

Analysis

AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achieve remote code execution. CVSS Score: 9.1. Published: 2026-08-11T13:19:05.813.

Indicators of Compromise (1)

CVE (1)
CVE-2026-72748
Source Attribution

Originally published by NIST NVD on Aug 11, 2026. Verified by: NIST.

Related Threats