CRITICAL 9.8 CVE-2026-86189 Published 5 Sept 2026

AVideo Path Traversal Vulnerability

Worried this affects one of your servers?

AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations.

Attackers can replay previously issued ciphertext as a notifyCode token to bypass authentication and write files to the application root and subdirectories.

Reference: CVE-2026-86189 on NVD

← Back to Security News