Summary
CVE-2026-56345 is a critical authentication bypass vulnerability (CWE-287) in the Meet plugin of AVideo, affecting all versions through 29.0. The flaw allows a remote attacker who possesses the Meet shared secret to forge a file upload request that establishes a fully authenticated session as any user — including administrators — without knowing their password. No patch is currently available; administrators should apply available workarounds immediately.
Technical details
- Root cause: The
uploadRecordedVideo.json.phpendpoint extracts the targetusers_iddirectly from the uploaded filename usingexplode('-', $_FILES['upl']['name'])[0], then calls$userObject->login(true, true)— a passwordless login that creates a full authenticated session. No ownership verification or signature check is performed on this user-controlled value. - Trigger conditions: An attacker must possess the Meet shared secret. The advisory confirms this secret can be obtained through path-traversal vulnerabilities present in AVideo, or recovered via timing attacks against the
checkToken.json.phpendpoint, which uses non-constant-time comparison. - Attack vector: Remote, unauthenticated (no existing session required). The attacker sends an HTTP POST to
uploadRecordedVideo.json.phpwith a Bearer token and a crafted filename such as1-anything.mp4, where the leading digit is the target user’s ID. - Impact: The server responds with a fully authenticated
PHPSESSIDcookie valid for the targeted account. By targeting user ID1(typically the admin), an attacker achieves complete account takeover with administrative privileges — compromising confidentiality, integrity, and availability of the platform and its data.
Affected software
- AVideo (WWBN/AVideo) — all versions through 29.0 (the current latest release)
Severity
CVSS v3.1 Base Score: 8.1 (HIGH)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
(CVSS 4.0 score: 9.2 CRITICAL — CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
Mitigation and recommended actions
- No patch is currently available. As of the date of this publication, AVideo v29.0 remains the latest release and contains the vulnerability. Monitor the WWBN/AVideo GitHub repository for a remediation release.
- Disable or restrict the Meet plugin: If the AVideo Meet plugin is not required, disable it or remove the
uploadRecordedVideo.json.phpendpoint from public access at the web server or firewall level. - Block external access to sensitive endpoints: Apply network-level controls to restrict access to
uploadRecordedVideo.json.phpandcheckToken.json.phpto trusted internal IP ranges only. - Rotate and harden the Meet shared secret: Replace any configuration-derived shared secret with a randomly generated 256-bit value to raise the cost of secret recovery.
- Audit active sessions: Review server session logs for unexpected authenticated sessions, particularly for administrative user accounts.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

