CVE-2026-35450: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-35450 is an unauthenticated information disclosure vulnerability in WWBN AVideo affecting the plugin/API/check.ffmpeg.json.php endpoint, which exposes FFmpeg remote server configuration and connectivity status without requiring any authentication. It affects AVideo versions up to and including 26.0, with no patched version listed at the time of disclosure. The advisory was published on April 2, 2026, by DanielnetoDotCom via the WWBN/AVideo GitHub Security Advisory. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, AVideo Advisory).

Technical details

The root cause is a missing authentication check (CWE-306) on the plugin/API/check.ffmpeg.json.php endpoint. While all sibling FFmpeg management endpoints — kill.ffmpeg.json.php, list.ffmpeg.json.php, and ffmpeg.php — enforce User::isAdmin() authorization, the check.ffmpeg.json.php file omits this guard entirely, allowing any unauthenticated network request to probe the FFmpeg remote server configuration and retrieve connectivity status. Exploitation requires no credentials, no user interaction, and no special network position — a simple HTTP GET or POST request to the exposed endpoint is sufficient (GitHub Advisory, AVideo Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to retrieve FFmpeg remote server configuration details and connectivity status from an AVideo instance, constituting an information disclosure with low confidentiality impact and no integrity or availability impact. The exposed data could assist attackers in mapping backend infrastructure, identifying FFmpeg server addresses or configurations, and planning further targeted attacks against the media processing pipeline. While the direct impact is limited, the reconnaissance value of the disclosed information could facilitate more severe follow-on attacks (GitHub Advisory).

Exploitability

A proof-of-concept exploit is publicly available in the form of a simple curl command targeting the vulnerable endpoint: curl "https://your-avideo-instance.com/plugin/API/check.ffmpeg.json.php". Feedly classifies this as a real exploit with high confidence, noting it directly reproduces the vulnerability without additional configuration. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The EPSS score is 0.034% (very low), and the vulnerability is not listed in the CISA KEV catalog (AVideo Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing AVideo instances (versions ≤ 26.0) using search engines like Shodan or Censys, or by browsing to known AVideo deployment paths.
  2. Send unauthenticated request: Issue a direct HTTP request to the vulnerable endpoint without any authentication headers or session cookies:
    curl "https://your-avideo-instance.com/plugin/API/check.ffmpeg.json.php"
  3. Retrieve FFmpeg configuration: The endpoint responds with FFmpeg remote server configuration details and connectivity status in JSON format, requiring no further interaction.
  4. Use for reconnaissance: Analyze the returned data to identify FFmpeg server addresses, ports, or configuration parameters that could be leveraged in follow-on attacks against the media processing infrastructure (AVideo Advisory).

Indicators of compromise

  • Network: Unexpected or repeated HTTP GET/POST requests to /plugin/API/check.ffmpeg.json.php from unauthenticated or unknown source IPs; requests lacking session cookies or authorization headers targeting this endpoint.
  • Logs: Web server access logs showing requests to check.ffmpeg.json.php from external or unfamiliar IP addresses, particularly in high volume or from automated tools (e.g., unusual User-Agent strings like curl/).
  • Application Logs: AVideo application logs showing access to the FFmpeg check endpoint without a corresponding authenticated session.

Mitigation and workarounds

No patched version of AVideo was available at the time of disclosure (all versions ≤ 26.0 are affected). As an immediate workaround, administrators should add an User::isAdmin() authentication check to plugin/API/check.ffmpeg.json.php consistent with the other FFmpeg management endpoints. Additionally, network-level controls such as firewall rules or web application firewall (WAF) policies should be used to restrict access to /plugin/API/check.ffmpeg.json.php to trusted IP ranges only. Monitor the WWBN/AVideo repository for an official patch release (GitHub Advisory, AVideo Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management