Description
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can request the endpoint with a known or guessed stream key to download recorded live video files without authentication or authorization checks.
Published: 2026-09-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated download of recorded video files
Action: Patch ASAP
AI Analysis

Impact

The vulnerability in WWBN AVideo surfaces when an attacker accesses the getRecordedFile.php endpoint without any authentication. The script expects a stream key and streams the requested FLV file from a temporary directory. Because the code lacks authentication checks, an attacker can supply a known or guessed stream key, causing the server to transmit the corresponding recorded live video to the requester. The result is a full disclosure of sensitive video content, with confidentiality entirely compromised. This flaw is classified as an unauthenticated read, aligning with CWE-306.

Affected Systems

The bug exists in the AVideo code base at commit c3edcc274c389816d434acadac07 deployment of WWBN AVideo that has not applied a subsequent patch or update is vulnerable. The affected component is the getRecordedFile.php file, which is part of the core AVideo distribution. No specific product version numbers are cited, but the vulnerability applies to the released code before the identified commit.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity vulnerability. Because the entry is publicly known but EPSS is not available, the current exploitation probability cannot be quantified, and the issue is not listed in CISA’s KEV catalog. Attackers could exploit the flaw over the network by issuing an unauthenticated HTTP GET request to the aforementioned endpoint with a valid stream key. Since no authentication or authorization gates exist, the risk to all users of the affected by anyone.

Generated by OpenCVE AI on September 11, 2026 at 14:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the latest version of WWBN AVideo that includes a fix for the unauthenticated read in getRecordedFile.php. If a patch is not yet released, upgrade to a newer release when available.
  • Restrict network access to the getRecordedFile.php endpoint by applying firewall rules or host‑based addresses or internal network segments.
  • Disable or remove the getRecordedFile.php endpoint from (e.g., require a valid token) until the official fix is applied.

Generated by OpenCVE AI on September 11, 2026 at 14:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Description WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can request the endpoint with a known or guessed stream key to download recorded live video files without authentication or authorization checks.
Title WWBN AVideo Unauthenticated File Read via getRecordedFile.php
First Time appeared Wwbn
Wwbn avideo
Weaknesses CWE-306
CPEs cpe:2.3:a:wwbn:avideo:-:*:*:*:*:*:*:*
Vendors & Products Wwbn
Wwbn avideo
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-11T14:03:05.394Z

Reserved: 2026-09-11T10:51:59.215Z

Link: CVE-2026-89250

cve-icon Vulnrichment

Updated: 2026-09-11T14:02:56.717Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T12:16:55.063

Modified: 2026-09-11T15:21:12.850

Link: CVE-2026-89250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:45:14Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function