THREAT OPS › Threat News › [NVD] CVE-2026-58003 (HIGH 7.1) — WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session coo
[NVD] CVE-2026-58003 (HIGH 7.1) — WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session coo
CVE-2026-58003 CVSS: 7.1 HIGH Published: 2026-08-22T13:16:38.673
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session cookie to permanently publish any embargoed video by mani
Indicators of compromise
- CVE-2026-58003cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-58003