Description
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes including live server configuration changes.
Published: 2026-09-01
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

WWBN AVideo contains a cross‑site request forgery flaw in the get_domain() and isSameDomain() functions that do not correctly validate referer origins. An attacker can supply requests from sibling subdomains or malformed long‑gTLD domains to trick the application into treating the request as legitimate. This leads to the ability to perform administrative ObjectYPT writes, including changes to live server configuration, potentially compromising confidentiality, integrity, and availability of the system.

Affected Systems

The affected product is WWBN AVideo, specifically the code base at commit 9c39d8c8. Users of this version are vulnerable and should verify the version in use against the commit hash or reviewed patch notes.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability. No EPSS score is available, and the flaw is not listed in CISA KEV catalog. The likely attack vector is a forged request originating from a controlled subdomain or specially crafted domain name that bypasses domain validation, allowing an unauthenticated attacker to perform privileged changes.

Generated by OpenCVE AI on September 1, 2026 at 23:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest AVideo update that includes the get_domain re‑validation fix
  • Restrict administrative endpoints to a whitelist of IP addresses or enforce SSH tunnel access
  • Configure the web server or application to reject requests lacking a valid Referer header or implement server‑side CSRF token validation

Generated by OpenCVE AI on September 1, 2026 at 23:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes including live server configuration changes.
Title WWBN AVideo Cross-Site Request Forgery via get_domain() validation
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-346
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-01T22:25:35.129Z

Reserved: 2026-09-01T20:37:00.841Z

Link: CVE-2026-84482

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-01T23:17:22.477

Modified: 2026-09-01T23:17:22.477

Link: CVE-2026-84482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T23:45:17Z

Weaknesses