CVE-2026-27732 | WWBN AVideo up to 21.x API Endpoint aVideoEncoder.json.php downloadURL server-side request forgery (GHSA-h39h-7cvg-q7j6)
A vulnerability has been found in WWBN AVideo up to 21.x and classified as critical. The affected element is an unknown function of the file aVideoEncoder.json.php of the component API Endpoint. Performing a manipulation of the argument downloadURL results in server-side request forgery.
This vulnerability is known as CVE-2026-27732. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.