CVE-2026-29058
Plain English Summary
AI-powered analysis for quick understanding
An attacker can run any command on the server without needing to log in, simply by manipulating a specific URL parameter in the software. This vulnerability can lead to complete control over the server, allowing the attacker to steal sensitive information or disrupt services, but it only affects versions prior to 7.0.
Technical Description
AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by injecting shell command substitution into the base64Url GET parameter. This can lead to full server compromise, data exfiltration (e.g., configuration secrets, internal keys, credentials), and service disruption. This issue has been patched in version 7.0.
CVSS Vector Analysis
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Quick Information
Published
Mar 6, 2026
about 1 month ago
Last Modified
Mar 10, 2026
28 days ago
Vendor
wwbn
Product
avideo-encoder