
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35450 is an unauthenticated information disclosure vulnerability in WWBN AVideo affecting the plugin/API/check.ffmpeg.json.php endpoint, which exposes FFmpeg remote server configuration and connectivity status without requiring any authentication. It affects AVideo versions up to and including 26.0, with no patched version listed at the time of disclosure. The advisory was published on April 2, 2026, by DanielnetoDotCom via the WWBN/AVideo GitHub Security Advisory. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, AVideo Advisory).
The root cause is a missing authentication check (CWE-306) on the plugin/API/check.ffmpeg.json.php endpoint. While all sibling FFmpeg management endpoints — kill.ffmpeg.json.php, list.ffmpeg.json.php, and ffmpeg.php — enforce User::isAdmin() authorization, the check.ffmpeg.json.php file omits this guard entirely, allowing any unauthenticated network request to probe the FFmpeg remote server configuration and retrieve connectivity status. Exploitation requires no credentials, no user interaction, and no special network position — a simple HTTP GET or POST request to the exposed endpoint is sufficient (GitHub Advisory, AVideo Advisory).
Successful exploitation allows an unauthenticated remote attacker to retrieve FFmpeg remote server configuration details and connectivity status from an AVideo instance, constituting an information disclosure with low confidentiality impact and no integrity or availability impact. The exposed data could assist attackers in mapping backend infrastructure, identifying FFmpeg server addresses or configurations, and planning further targeted attacks against the media processing pipeline. While the direct impact is limited, the reconnaissance value of the disclosed information could facilitate more severe follow-on attacks (GitHub Advisory).
A proof-of-concept exploit is publicly available in the form of a simple curl command targeting the vulnerable endpoint: curl "https://your-avideo-instance.com/plugin/API/check.ffmpeg.json.php". Feedly classifies this as a real exploit with high confidence, noting it directly reproduces the vulnerability without additional configuration. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is 0.034% (very low), and the vulnerability is not listed in the CISA KEV catalog (AVideo Advisory).
curl "https://your-avideo-instance.com/plugin/API/check.ffmpeg.json.php"/plugin/API/check.ffmpeg.json.php from unauthenticated or unknown source IPs; requests lacking session cookies or authorization headers targeting this endpoint.check.ffmpeg.json.php from external or unfamiliar IP addresses, particularly in high volume or from automated tools (e.g., unusual User-Agent strings like curl/).No patched version of AVideo was available at the time of disclosure (all versions ≤ 26.0 are affected). As an immediate workaround, administrators should add an User::isAdmin() authentication check to plugin/API/check.ffmpeg.json.php consistent with the other FFmpeg management endpoints. Additionally, network-level controls such as firewall rules or web application firewall (WAF) policies should be used to restrict access to /plugin/API/check.ffmpeg.json.php to trusted IP ranges only. Monitor the WWBN/AVideo repository for an official patch release (GitHub Advisory, AVideo Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."