#VU125504 Missing Authorization in AVideo - CVE-2026-35179
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to modify content on the platform's Instagram account.
The vulnerability exists due to missing authorization in publishInstagram.json.php when handling requests to proxy Instagram Graph API calls. A remote attacker can send a specially crafted request with user-controlled Graph API parameters to modify content on the platform's Instagram account.
The endpoint forwards the request to Facebook's servers and uses the server's IP address for the API calls.