CRITICALVulnerability
Verified
Global
NVD CRITICAL: CVE-2026-86189 — WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php th...
·Source: NIST NVD
Updated:
Executive Summary
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the applicatio
Analysis
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never validated, to bypass authentication and write files to the application root and subdirectories. CVSS Score: 9.8. Published: 2026-09-05T13:18:14.000.