Missing Authentication for Critical Function in AVideo - CVE-2026-56346
Published: May 4, 2026 / Updated: September 14, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to missing authentication for a critical function in decryptMessage.json.php when handling PGP decryption requests. A remote attacker can send specially crafted decryption requests to disclose sensitive information and cause a denial of service.
Submitted private key material may be exposed in server memory or logging infrastructure depending on deployment configuration.