{"id":"CVE-2026-43885","aliases":["GHSA-xr49-f4rh-qcjf"],"url":"https://o3.security/vulnerability/CVE-2026-43885","summary":"WWBN AVideo: Exposure of Sensitive Information to an Unauthorized Actor and Missing Authorization","details":"WWBN AVideo is an open source video platform. In versions up to and including 29.0, an unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints (e.g. users_list) without logging in. Commit 1c36f229d0a103528fb9f64d0a1cc0e1e8f5999b contains an updated fix.","published":"2026-05-11T20:45:21.425Z","modified":"2026-08-12T03:51:34.570151860Z","cvss":null,"epss":{"score":0.00257,"percentile":0.16988,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"wwbn/avideo","fixedVersion":null}],"fix":{"url":"https://github.com/WWBN/AVideo/commit/1c36f229d0a103528fb9f64d0a1cc0e1e8f5999b","label":"WWBN/AVideo@1c36f22"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43885.json"},{"type":"ADVISORY","url":"https://github.com/WWBN/AVideo/security/advisories/GHSA-xr49-f4rh-qcjf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-43885"},{"type":"FIX","url":"https://github.com/WWBN/AVideo/commit/1c36f229d0a103528fb9f64d0a1cc0e1e8f5999b"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:34.570151860Z"}}