#VU125505 Missing Authentication for Critical Function in AVideo - CVE-2026-35450
Published: April 8, 2026
AVideo
World Wide Broadcast Network
Description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to missing authentication for a critical function in plugin/API/check.ffmpeg.json.php when handling requests to the FFmpeg status endpoint. A remote attacker can send a request to the endpoint to disclose sensitive information.
The issue reveals whether the platform uses a standalone FFmpeg server and its current reachability, which may aid infrastructure reconnaissance.