CVE-2026-34740 is a stored Server-Side Request Forgery (SSRF) vulnerability affecting WWBN AVideo versions 26.0 and prior. Authenticated users with upload permissions can exploit this by storing arbitrary internal network URLs in the EPG link feature, which the server then fetches without proper validation. This medium-severity vulnerability (CVSS 6.5) allows remote attackers with low privileges to scan internal networks, access cloud metadata, and interact with internal services, leading to a high confidentiality impact. Although AVideo includes an SSRF prevention function, it is not called in the vulnerable code path. Currently, there are no publicly available patches, exploit code, or evidence of active exploitation, with minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 26.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.