THREAT OPS › Threat News › [NVD] CVE-2026-86189 (CRITICAL 9.8) — WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext a
[NVD] CVE-2026-86189 (CRITICAL 9.8) — WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext a
CVE-2026-86189 CVSS: 9.8 CRITICAL Published: 2026-09-05T13:18:14.000
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never
Indicators of compromise
- CVE-2026-86189cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86189