CVE-2026-33482 is a high-severity OS command injection vulnerability affecting WWBN AVideo versions up to and including 26.0. It arises from insufficient sanitization in the `sanitizeFFmpegCommand()` function, which fails to neutralize bash command substitution syntax (`$()`), enabling unauthenticated attackers to execute arbitrary commands on the standalone encoder server. Rated 8.1 High (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), successful exploitation, though requiring high attack complexity, grants full control over the affected system. Currently, there is no evidence of active exploitation, public exploit code, or inclusion in CISA's Known Exploited Vulnerabilities catalog, with only minimal community discussion observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 26.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.