CVE-2026-39370 | WWBN AVideo up to 26.0 aVideoEncoder.json.php downloadURL server-side request forgery (GHSA-cmcr-q4jf-p6q9)
A vulnerability, which was classified as critical, was found in WWBN AVideo up to 26.0. This vulnerability affects unknown code of the file objects/aVideoEncoder.json.php. Such manipulation of the argument downloadURL leads to server-side request forgery.
This vulnerability is uniquely identified as CVE-2026-39370. The attack can be launched remotely. No exploit exists.