Server-Side Request Forgery (SSRF) in AVideo - CVE-2026-56342

 

Server-Side Request Forgery (SSRF) in AVideo - CVE-2026-56342

Published: May 4, 2026 / Updated: September 14, 2026


Vulnerability identifier: #VU129517
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-56342
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information from internal, localhost, or cloud metadata services.

The vulnerability exists due to server-side request forgery in plugin/Live/test.php when processing the statsURL parameter without isSSRFSafeURL() validation. A remote privileged user can send a specially crafted request to disclose sensitive information from internal, localhost, or cloud metadata services.

The endpoint returns the full fetched response content in the HTML output, and the issue affects authenticated admin access.


Affected software

AVideo

How to mitigate CVE-2026-56342

Install security update from vendor's website.

AVideo - update to 29.0

External References

Related Security Bulletins