CVE-2026-39368: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-39368 is a Stored Server-Side Request Forgery (SSRF) vulnerability in WWBN AVideo, an open source video platform. The flaw exists in the Live restream log callback flow, where an attacker-controlled restreamerURL is accepted and later fetched server-side, enabling authenticated streamers to proxy requests to internal or loopback services. All versions up to and including 26.0 are affected; no patched version has been released as of the advisory date. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, GHSA-q4x6-6mm2-crg9).

Technical details

The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and stems from the absence of URL validation on the restreamerURL parameter at storage time in the Live restream log feature. The exploitable chain involves four endpoints: getRestream.json.php exposes a tokenForAction, verifyTokenForAction.json.php exchanges it for a responseToken, Live_restreams_logs/add.json.php accepts an attacker-controlled restreamerURL without constraining it to trusted destinations, and subsequent calls to getRestream.json.php or getAction.json.php fetch the stored URL server-side. Because the responseToken was accepted without binding it to an expected callback host, any HTTP-reachable address — including loopback (127.0.0.1) and RFC-1918 internal ranges — could be specified as the callback destination (GitHub Advisory, GHSA-q4x6-6mm2-crg9).

Impact

Successful exploitation allows an authenticated low-privilege streamer to use the AVideo server as an HTTP proxy to internal-only services, effectively bypassing network access controls that rely on network locality. Sensitive assets that could be exposed include local admin panels, internal-only APIs, and cloud instance metadata services (e.g., 169.254.169.254). The impact is limited to confidentiality (CVSS Confidentiality: High) with no direct integrity or availability impact, though data obtained from internal services could facilitate further lateral movement or privilege escalation (GHSA-q4x6-6mm2-crg9).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been observed as of the advisory date. The vulnerability requires an authenticated account with streaming permissions, limiting the attacker pool but not eliminating risk in multi-tenant or community-facing deployments. The EPSS score is approximately 0.036% (11th percentile), indicating a low near-term exploitation probability. The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog (GitHub Advisory).

Exploitation steps

  1. Authenticate: Log in to the AVideo instance as a non-admin user who has been granted streaming permission.
  2. Create a restream destination: Set up a normal restream destination through the Live plugin interface to establish a valid restream row.
  3. Generate a transmission history row: Trigger POST /plugin/Live/view/Live_restreams/testRestreamer.json.php to create a live transmission history entry.
  4. Obtain tokenForAction: Send GET /plugin/Live/view/getRestream.json.php?live_transmitions_history_id=<id>&restreams_id=<id> and extract the tokenForAction value from the response.
  5. Exchange for responseToken: Send POST /plugin/Live/view/Live_restreams/verifyTokenForAction.json.php with the extracted token to receive a valid responseToken.
  6. Store malicious callback URL: Send POST /plugin/Live/view/Live_restreams_logs/add.json.php with restreamerURL=http://127.0.0.1:9999/index.php (or any internal target) using the responseToken.
  7. Trigger server-side fetch: Call GET /plugin/Live/view/getRestream.json.php again; the server fetches the stored loopback URL and returns the internal service's response through the normal application endpoint, exposing internal data to the attacker (GHSA-q4x6-6mm2-crg9).

Indicators of compromise

  • Network: Outbound HTTP requests from the AVideo server to loopback (127.0.0.1, ::1) or RFC-1918 addresses (10.x.x.x, 172.16–31.x.x, 192.168.x.x) originating from the web server process; requests to cloud metadata endpoints such as 169.254.169.254.
  • Logs: Web server access logs showing repeated or unusual POST requests to /plugin/Live/view/Live_restreams_logs/add.json.php with non-standard restreamerURL values; GET requests to /plugin/Live/view/getRestream.json.php shortly after such POSTs from the same session.
  • Application Logs: AVideo application logs recording fetch operations against internal IP addresses or hostnames not matching configured restreamer endpoints.
  • File System: No specific file artifacts expected, but unexpected configuration changes to restream destinations may indicate reconnaissance activity (GHSA-q4x6-6mm2-crg9).

Mitigation and workarounds

No patched version of WWBN AVideo has been released as of the advisory date (affected versions ≤ 26.0). The maintainer confirmed the fix approach involves validating restreamerURL against explicitly configured restreamer endpoints at storage time and re-validating before any server-side fetch. Until a patch is available, operators should implement network egress controls to block the AVideo server from making outbound requests to loopback and internal IP ranges, restrict the Live restream feature to highly trusted users, and monitor callback URL configurations for suspicious patterns (GHSA-q4x6-6mm2-crg9, GitHub Advisory).

Community reactions

The vulnerability was reported by researcher threalwinky and published by maintainer DanielnetoDotCom on April 6, 2026. The maintainer confirmed the vulnerability and described the intended fix approach in the advisory. No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified (GHSA-q4x6-6mm2-crg9).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management