CRITICAL
9.8 CVE-2026-86189 Published 5 Sept 2026
AVideo Path Traversal Vulnerability
Worried this affects one of your servers?
AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations.
Attackers can replay previously issued ciphertext as a notifyCode token to bypass authentication and write files to the application root and subdirectories.
Reference: CVE-2026-86189 on NVD
← Back to Security News