CVE-2026-39368: Wwbn Avideo

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restreamerURL and later fetched that stored URL server-side, enabling stored SSRF for authenticated streamers. The vulnerable flow allowed a low-privilege user with streaming permission to store an arbitrary callback URL and trigger server-side requests to loopback or internal HTTP services through the restream log feature.

Affected products

  • Wwbn Avideo: up to and including 26.0

Published 2026-04-07. Last modified 2026-07-24.