CVE-2026-56345
AVideo Meet Plugin Authorization Bypass Enables Session Hijacking
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability exists in AVideo's Meet plugin that allows an attacker to bypass authorization. By obtaining a shared secret and uploading a specially crafted file, an attacker can hijack user sessions, including administrative ones, potentially leading to a full account takeover. This issue impacts system security and