CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-86189 — WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php th...

·Source: NIST NVD

Updated:

Executive Summary

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the applicatio

Analysis

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the application root and subdirectories. CVSS Score: 9.8. Published: 2026-09-05T13:18:14.000.

Indicators of Compromise (1)

CVE (1)
CVE-2026-86189
Source Attribution

Originally published by NIST NVD on Sep 5, 2026. Verified by: NIST.

Related Threats