External risk intelligence

Stored XSS in WWBN AVideo via Doubly Encoded Video Titles.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-105086

WWBN AVideo is a web-based video platform frequently deployed as a public-facing service for hosting and sharing content. The vulnerability affects pages like trending, gallery, and embed views, which are typical public-facing components of such an application, making the vulnerable surface commonly exposed to internet users.

Cross-site Scripting

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A stored cross-site scripting vulnerability in WWBN AVideo allows authenticated users to inject malicious code through specially crafted video titles. This could potentially lead to the execution of arbitrary HTML and script content on pages viewed by other users, impacting site integrity and user experience.

  • The issue allows code injection via video titles.
  • This impacts user-facing video content pages.
  • Confirm WWBN AVideo relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker with uploader privileges can inject malicious HTML into video titles, even if the content is doubly encoded. This markup can then execute when users view trending, gallery, embed, or playlist pages, potentially leading to unauthorized actions or information disclosure.

  • Authenticated uploader access required.
  • Stored HTML in video titles.
  • Risk of code execution in user views.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow authenticated users to inject HTML into video titles, which may then execute as stored cross-site scripting on pages like trending, gallery, and embed views. The impact is contingent on the specific configuration and exposure of these pages.

  • Stored HTML in video titles.
  • Injected HTML executes in user browsers.
  • Compromised user trust and session integrity.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability likely affects application owners and platform teams responsible for WWBN AVideo deployments. The first step is to identify all instances of WWBN AVideo, confirm their accessibility and business criticality, and then identify the accountable owner for remediation planning.

  • Application owners should own the issue.
  • Verify public or internal reachability first.
  • Plan remediation or implement temporary risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WWBN AVideo?

WWBN AVideo is an open-source, web-based video platform designed for hosting and streaming multimedia content. It provides features typical of video-sharing sites, such as galleries, playlists, and embeddable players, allowing users to manage, upload, and view media collections within their own hosted environments.

How does this CVE-2026-105086 vulnerability work?

This is a stored cross-site scripting (XSS) vulnerability, classified as CWE-79. It occurs because the application processes video titles through a cleanup function that runs twice, inadvertently allowing doubly-encoded HTML entities to bypass security filters. Once stored, this malicious markup executes automatically when other users view affected pages like video galleries or embeds.

What must an attacker do to trigger this bug?

An attacker needs an account with uploader privileges to submit a specifically crafted video title containing doubly-encoded entities. The vulnerability does not trigger if a user lacks the permissions to upload or edit video metadata, as the malicious payload must be submitted through the title input field during the upload or update process.

Do I need to worry if my AVideo instance is internal?

According to Halo Surface Signal, WWBN AVideo is frequently deployed as a public-facing service. While internal instances face a lower risk from external actors, any deployment where video content is accessible to a broad user base increases the likelihood of impact. Assess whether your specific instance is internet-facing or restricted to trusted internal users to gauge your priority.

What are the first steps to take if I run WWBN AVideo?

Begin by identifying all active instances of WWBN AVideo in your environment and verifying who is responsible for their maintenance. Determine if these platforms are public-facing or internal, and consult the vendor's provided security resources or official repositories to identify if a patch or update is available for your specific software version.

References