OVERVIEW CVE-2026-40928 is a Cross-Site Request Forgery (CSRF) vulnerability affecting WWBN AVideo versions 29.0 and prior. Multiple JSON endpoints under the objects directory lack anti-CSRF protections and accept state-changing requests via GET parameters or REQUEST data, allowing attackers to perform unauthorized actions on behalf of authenticated users without their knowledge. SEVERITY The vulnerability carries a CVSS score of 5.4 (Medium) with a network-based attack vector requiring minimal complexity and user interaction. An attacker can exploit this by tricking a logged-in victim into visiting a malicious webpage containing simple HTML elements like image tags or forms. The impact includes the ability to manipulate user likes/dislikes on comments, post comments authored by the victim with attacker-controlled text, and delete assets from categories if the victim has administrative rights. While the integrity and availability impacts are limited in scope, the unauthorized actions persist under the victim's identity. EXPLOITATION STATUS There is no indication of active exploitation in the wild, as the vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog and maintains an inactive status on threat tracking lists. The EPSS score of 0.00015 indicates this vulnerability ranks lower than 99.97 percent of all published CVEs in terms of exploitation likelihood. A fix is available in commit 7aaad601bd9cd7b993ba0ee1b1bea6c32ee7b77c, and organizations running affected versions should apply patches to eliminate the CSRF attack surface.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 29.0CPE matchmatch criteria | cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.