CVE-2026-41055
8.6WWBN · AVideo
WWBN AVideo contains a Server-Side Request Forgery vulnerability due to an incomplete fix for DNS Time-of-Check to Time-of-Use flaws, allowing attackers to access internal network resources.
Executive summary
A critical SSRF vulnerability in WWBN AVideo versions 29.0 and below allows unauthenticated attackers to bypass security controls and reach internal network endpoints.
Vulnerability
The application utilizes an incomplete isSSRFSafeURL() validation mechanism that is susceptible to DNS rebinding attacks. This allows an unauthenticated attacker to manipulate the LiveLinks proxy to redirect HTTP requests toward sensitive internal infrastructure.
Business impact
The vulnerability carries a CVSS score of 8.6, reflecting its high impact and ease of exploitability. Successful exploitation enables unauthorized access to internal services or metadata endpoints that are otherwise protected by a firewall, potentially leading to data exfiltration or further lateral movement within the environment.
Remediation
Immediate Action: Update to the latest version of WWBN AVideo and ensure the fixes provided in commit 8d8fc0cadb425835b4861036d589abcea4d78ee8 are applied.
Proactive Monitoring: Monitor server access logs for suspicious outbound requests originating from the AVideo platform, particularly those targeting internal IP ranges or local host services.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to block suspicious URL parameters and restrict outbound traffic from the application server to internal network segments.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high severity and the availability of proof-of-concept material, organizations running WWBN AVideo must prioritize this update. Administrators should verify their current version and apply the upstream patches immediately to prevent unauthorized internal network access.