Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-56345 – Authentication Bypass – AVideo Meet Plugin through v29.0

Be the first to know when new zero-days emerge:

Summary

CVE-2026-56345 is a critical authentication bypass vulnerability (CWE-287) in the Meet plugin of AVideo, affecting all versions through 29.0. The flaw allows a remote attacker who possesses the Meet shared secret to forge a file upload request that establishes a fully authenticated session as any user — including administrators — without knowing their password. No patch is currently available; administrators should apply available workarounds immediately.

Technical details

  • Root cause: The uploadRecordedVideo.json.php endpoint extracts the target users_id directly from the uploaded filename using explode('-', $_FILES['upl']['name'])[0], then calls $userObject->login(true, true) — a passwordless login that creates a full authenticated session. No ownership verification or signature check is performed on this user-controlled value.
  • Trigger conditions: An attacker must possess the Meet shared secret. The advisory confirms this secret can be obtained through path-traversal vulnerabilities present in AVideo, or recovered via timing attacks against the checkToken.json.php endpoint, which uses non-constant-time comparison.
  • Attack vector: Remote, unauthenticated (no existing session required). The attacker sends an HTTP POST to uploadRecordedVideo.json.php with a Bearer token and a crafted filename such as 1-anything.mp4, where the leading digit is the target user’s ID.
  • Impact: The server responds with a fully authenticated PHPSESSID cookie valid for the targeted account. By targeting user ID 1 (typically the admin), an attacker achieves complete account takeover with administrative privileges — compromising confidentiality, integrity, and availability of the platform and its data.

Affected software

  • AVideo (WWBN/AVideo) — all versions through 29.0 (the current latest release)

Severity

CVSS v3.1 Base Score: 8.1 (HIGH)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

(CVSS 4.0 score: 9.2 CRITICAL — CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)

Mitigation and recommended actions

  • No patch is currently available. As of the date of this publication, AVideo v29.0 remains the latest release and contains the vulnerability. Monitor the WWBN/AVideo GitHub repository for a remediation release.
  • Disable or restrict the Meet plugin: If the AVideo Meet plugin is not required, disable it or remove the uploadRecordedVideo.json.php endpoint from public access at the web server or firewall level.
  • Block external access to sensitive endpoints: Apply network-level controls to restrict access to uploadRecordedVideo.json.php and checkToken.json.php to trusted internal IP ranges only.
  • Rotate and harden the Meet shared secret: Replace any configuration-derived shared secret with a randomly generated 256-bit value to raise the cost of secret recovery.
  • Audit active sessions: Review server session logs for unexpected authenticated sessions, particularly for administrative user accounts.

IONIX Status

The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

References

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge