CVE-2026-35179: Wwbn Avideo

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Instagram Graph API. The endpoint accepts user-controlled parameters including an access token, container ID, and Instagram account ID, and passes them directly to the Graph API via InstagramUploader::publishMediaIfIsReady(). This allows any unauthenticated user to make arbitrary Graph API calls through the server, potentially using stolen tokens or abusing the platform's own credentials.

Affected products

  • Wwbn Avideo: up to and including 26.0

Published 2026-04-06. Last modified 2026-07-24.