THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-86189 (CRITICAL 9.8) — WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext a

[NVD] CVE-2026-86189 (CRITICAL 9.8) — WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext a

mednvdPublished 2026-09-05

CVE-2026-86189 CVSS: 9.8 CRITICAL Published: 2026-09-05T13:18:14.000

WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can replay any previously issued ciphertext as a notifyCode token, which is decrypted but never

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-86189