Description
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebRTC/status.json.php and receive JSON containing the absolute filesystem path of the WebRTC2RTMP helper binary (revealing the document-root path), the configured WebRTC port, file_exists/is_executable status for the binary, the contents of the WebRTC log/JSON files (videos/WebRTC2RTMP.log) when present, and whether the configured port is reachable on loopback (127.0.0.1) and on the public address. The endpoint performs no User::isLogged(), User::isAdmin(), or forbiddenPage() check. The issue was unfixed at the time of reporting.
Published: 2026-09-11
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remotely unprivileged Information Disclosure
Action: Apply Access Control
AI Analysis

Impact

A missing authentication and authorization check in the WebRTC plugin’s status.json.php endpoint lets any remote, unauthenticated user obtain a JSON payload that reveals the absolute filesystem path to the WebRTC2RTMP helper binary, the configured WebRTC port, the binary’s exist‑and‑executable status, the contents of log files when present, and the reachability of the configured port on loopback and on the public interface. The exposed data reveals internal directory structure and runtime configuration, potentially aiding further attacks. This weakness is a classic CWE‑200 Information Exposure flaw.

Affected Systems

The vulnerability affects WWBN AVideo with the WebRTC plugin in all releases that include the code at commit c3edcc274c389816d434acadac07ee78eaf330c1 as of the reporting date. All current releases contain the vulnerability; a patch has not yet been released.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity risk. No EPSS score is available, and the vulnerability is not currently listed in CISA’s KEV catalog, so the quantified likelihood of exploitation is unknown. The attack can be carried out with no authentication by simply sending an HTTP GET request to /plugin/WebRTC/status.json.php on the target where the WebRTC plugin is installed. Because the endpoint performs no User::isLogged(), User::isAdmin(), or forbiddenPage() checks, any unauthenticated actor can gain the described information, which could facilitate further reconnaissance or exploitation steps.

Generated by OpenCVE AI on September 11, 2026 at 14:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check for vendor patch when available
  • If a patch is not yet available, temporarily disable the WebRTC plugin by removing or renaming the plugin directory or by configuring the web server to deny access to /plugin/WebRTC/status.json.php
  • Configure web server access controls (e.g., .htaccess or server config) to return HTTP 403 for unauthenticated requests to /plugin/WebRTC/status.json.php until the patch is deployed

Generated by OpenCVE AI on September 11, 2026 at 14:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebRTC/status.json.php and receive JSON containing the absolute filesystem path of the WebRTC2RTMP helper binary (revealing the document-root path), the configured WebRTC port, file_exists/is_executable status for the binary, the contents of the WebRTC log/JSON files (videos/WebRTC2RTMP.log) when present, and whether the configured port is reachable on loopback (127.0.0.1) and on the public address. The endpoint performs no User::isLogged(), User::isAdmin(), or forbiddenPage() check. The issue was unfixed at the time of reporting.
Title AVideo WebRTC Plugin Information Disclosure via status.json.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-200
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T12:33:32.464Z

Reserved: 2026-09-11T10:51:31.663Z

Link: CVE-2026-89248

cve-icon Vulnrichment

Updated: 2026-09-11T12:33:28.335Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:54.730

Modified: 2026-09-11T15:21:12.850

Link: CVE-2026-89248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T17:15:06Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor