Information disclosure in AVideo - CVE-2026-35452

 

Information disclosure in AVideo - CVE-2026-35452

Published: April 8, 2026


Vulnerability identifier: #VU125508
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-35452
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: World Wide Broadcast Network
Affected software:
AVideo

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in plugin/CloneSite/client.log.php when handling requests to the log endpoint. A remote attacker can send a request to the endpoint to disclose sensitive information.

If the CloneSite feature has been used, the exposed log may contain internal filesystem paths, remote server URLs, SSH connection metadata, and SQL dump file locations.


How to mitigate CVE-2026-35452

Install security update from vendor's website.

Sources