MEDIUM
WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image404Raw.php`
Published May 29, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.58%
Description
WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk that the PHP user can open — including private user-profile photos that the application's normal serving wrappers gate behind ACLs, admin-uploaded thumbnails, encrypted-video poster frames, and image content under sibling-app directories reachable via .. traversal. The endpoint requires no authentication.
Affected products
-
Affected
- ≤ 29.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (3)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33305 Advisory
- https://github.com/WWBN/AVideo/security/advisories/GHSA-w4qq-74h6-58wq exploitx_refsource_CONFIRMMitigationVendor Advisory
- https://github.com/advisories/GHSA-w4qq-74h6-58wq Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-46337
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33305 | Advisory | |
| https://github.com/WWBN/AVideo/security/advisories/GHSA-w4qq-74h6-58wq | exploitx_refsource_CONFIRMMitigationVendor Advisory | |
| https://github.com/advisories/GHSA-w4qq-74h6-58wq | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-46337 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 29, 2026
Updated May 29, 2026
Reserved May 13, 2026
Link CVE-2026-46337
CISA Vulnrichment
Updated May 29, 2026
Red Hat
No data
GitHub
Link GHSA-W4QQ-74H6-58WQ