CVE-2026-41055

8.6

WWBN · AVideo

WWBN AVideo contains a Server-Side Request Forgery vulnerability due to an incomplete fix for DNS Time-of-Check to Time-of-Use flaws, allowing attackers to access internal network resources.

Executive summary

A critical SSRF vulnerability in WWBN AVideo versions 29.0 and below allows unauthenticated attackers to bypass security controls and reach internal network endpoints.

Vulnerability

The application utilizes an incomplete isSSRFSafeURL() validation mechanism that is susceptible to DNS rebinding attacks. This allows an unauthenticated attacker to manipulate the LiveLinks proxy to redirect HTTP requests toward sensitive internal infrastructure.

Business impact

The vulnerability carries a CVSS score of 8.6, reflecting its high impact and ease of exploitability. Successful exploitation enables unauthorized access to internal services or metadata endpoints that are otherwise protected by a firewall, potentially leading to data exfiltration or further lateral movement within the environment.

Remediation

Immediate Action: Update to the latest version of WWBN AVideo and ensure the fixes provided in commit 8d8fc0cadb425835b4861036d589abcea4d78ee8 are applied.

Proactive Monitoring: Monitor server access logs for suspicious outbound requests originating from the AVideo platform, particularly those targeting internal IP ranges or local host services.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to block suspicious URL parameters and restrict outbound traffic from the application server to internal network segments.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high severity and the availability of proof-of-concept material, organizations running WWBN AVideo must prioritize this update. Administrators should verify their current version and apply the upstream patches immediately to prevent unauthorized internal network access.

More WWBN CVEs

Sources