Server-Side Request Forgery (SSRF) in AVideo - CVE-2026-27732

 

Server-Side Request Forgery (SSRF) in AVideo - CVE-2026-27732

Published: April 8, 2026


Vulnerability identifier: #VU125434
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27732
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform server-side requests to arbitrary URLs and disclose sensitive information.

The vulnerability exists due to server-side request forgery in aVideoEncoder.json.php when processing the downloadURL parameter. A remote user can supply a crafted URL to perform server-side requests to arbitrary URLs and disclose sensitive information.

The issue can be used to reach internal network endpoints, including internal APIs and metadata services.


Affected software

AVideo

How to mitigate CVE-2026-27732

Install security update from vendor's website.

AVideo - update to 22.0

External References

Related Security Bulletins