External risk intelligence

WWBN AVideo Unauthenticated Path Traversal Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-86189

AVideo is a web-based video sharing and streaming application designed to be accessed over a network. As a web application, it is commonly deployed as an internet-facing service to facilitate media streaming and user interaction, making its endpoints, including the vulnerable notification script, typically reachable from the public internet in standard deployment patterns.

Path Traversal

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in a video platform's notification script could allow unauthorized users to write files to the application's server. This is because a component that handles notifications does not properly validate received security tokens, enabling attackers to bypass authentication and potentially manipulate files. The main concern is confirming relevance and exposure.

  • Unauthenticated attackers can write files to the server.
  • It allows bypassing authentication for file manipulation.
  • Confirm relevance and exposure of this video platform.

Attack Path

How an attacker could exploit the issue

Attackers can exploit this vulnerability by sending a crafted request to the `notify.ffmpeg.json.php` script. This request allows them to bypass authentication and write files to any location on the server, potentially overwriting critical system files or injecting malicious content.

  • Unauthenticated network access required.
  • Vulnerable script accepts arbitrary file paths.
  • Arbitrary file write and system compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to write files to arbitrary locations within the application's directory. This occurs when a specially crafted path is provided in the `avideoRelativePath` parameter of the `notify.ffmpeg.json.php` script, bypassing authentication by replaying a previously issued ciphertext as a `notifyCode` token.

  • Application files could be overwritten.
  • Arbitrary file writes are possible.
  • Service interruption or compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The WWBN AVideo notify.ffmpeg.json.php component is vulnerable to unauthenticated path traversal, allowing attackers to write files to arbitrary locations. Responsibility for this vulnerability likely falls to the application owner or the platform team responsible for managing the AVideo deployment. The first practical step is to identify all instances of AVideo, confirm their exposure and criticality, and then engage the appropriate team for remediation planning based on risk.

  • Application owners must prioritize this.
  • Verify external access and critical assets.
  • Plan remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WWBN AVideo?

WWBN AVideo is a web-based video sharing and streaming platform. It provides the infrastructure for users to upload, manage, and broadcast media content over a network. Because it functions as a media server, it is often deployed in environments where accessibility and external connectivity are essential for streaming purposes.

What does CVE-2026-86189 mean?

This CVE describes a path traversal vulnerability, classified as CWE-73 (External Control of File Name or Path). Essentially, the software fails to properly check where a file is being saved. An attacker can manipulate the file path input to trick the application into writing files into restricted directories, effectively allowing them to place or overwrite files anywhere within the application's root or subdirectories.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a crafted request to the notify.ffmpeg.json.php script. They bypass authentication by replaying a previously issued ciphertext as a valid security token; the system decrypts this but fails to validate it. The vulnerability is triggered when the attacker provides an arbitrary destination path in the avideoRelativePath parameter. Simply visiting the site or standard user interaction does not trigger the bug; it requires specific, malicious input.

Is my instance of AVideo at risk?

According to Halo Surface Signal, AVideo is typically deployed as an internet-facing service to facilitate media streaming. If your instance is reachable from the public internet, it falls into the 'likely' risk category for external access. You should evaluate your network configuration to determine if this specific notification script is exposed to untrusted networks.

What is the first step to address this issue?

Begin by identifying all running instances of the AVideo platform within your environment. Once you have a complete inventory, verify the network exposure of these instances, prioritizing those accessible from the internet. Coordinate with your platform or IT team to assess the risk to your specific deployment and prepare for remediation actions provided by the vendor.

References