CVE-2026-72748 PUBLISHED

AVideo Unauthenticated Arbitrary File Write via aVideoEncoderChunk.json.php

Assigner: VulnCheck
Reserved: 10.08.2026 Published: 11.08.2026 Updated: 11.08.2026

AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achieve remote code execution.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor WWBN
Product AVideo
Versions Default: unaffected
  • Version 29.0 is affected

Credits

  • DhiyaneshGeek reporter
  • neo-ai-engineer reporter

References

Problem Types

  • Missing Authentication for Critical Function CWE