Insufficient Session Expiration in AVideo - CVE-2026-34362

 

Insufficient Session Expiration in AVideo - CVE-2026-34362

Published: April 8, 2026


Vulnerability identifier: #VU125485
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34362
CWE-ID: CWE-613
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and impersonate users over WebSocket connections.

The vulnerability exists due to insufficient session expiration in verifyTokenSocket() in plugin/YPTSocket/functions.php when validating WebSocket tokens. A remote user can reuse a captured or previously obtained WebSocket token to disclose sensitive information and impersonate users over WebSocket connections.

Admin tokens can expose real-time connection data for online users, including IP addresses, browser information, and page locations, and tokens remain usable even after account deletion, banning, or privilege demotion.


Affected software

AVideo

How to mitigate CVE-2026-34362

Install security update from vendor's website.

AVideo - update to 29.0

External References

Related Security Bulletins