CVE-2026-56341: AVideo - Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php

Published Jun 20, 2026
·
Updated

AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records. Unauthenticated attackers can retrieve all payment transaction data including agreement IDs, user financial records, and API responses via direct GET requests to vulnerable endpoints.

Affected Software

1 affected component
AVideo AVideo<=26.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Implement server-side authentication and authorization checks on all list.json.php endpoints in AVideo payment plugins so that unauthenticated GET requests cannot retrieve payment transaction data (agreement IDs, API responses, user financial records).

    AVideo payment plugin endpoints (list.json.php) authorization_required = true
  2. Compensating control

    Block or restrict external access to payment plugin list.json.php endpoints at the perimeter (web application firewall, reverse proxy, or web server). Configure rules to allow access only for authenticated/authorized users or trusted management IP ranges to prevent unauthenticated retrieval of payment data.

  3. Operational

    Assume PayPal tokens, Authorize.Net webhook secrets, and Bitcoin transaction records may have been exposed. Revoke/rotate any exposed PayPal tokens and Authorize.Net webhook keys, review affected transactions for fraud or misuse, and notify impacted users as appropriate.

Event History

Jun 20, 2026
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-56341?

CVE-2026-56341 has a high severity rating of 7.5.

2

How do I fix CVE-2026-56341?

To fix CVE-2026-56341, you should update to the latest version of AVideo that addresses the vulnerability.

3

What data is exposed in CVE-2026-56341?

CVE-2026-56341 exposes sensitive payment transaction data such as PayPal tokens, Authorize.Net webhooks, and Bitcoin transaction records.

4

Can an unauthenticated attacker exploit CVE-2026-56341?

Yes, an unauthenticated attacker can exploit CVE-2026-56341 to access payment log data.

5

Which versions of AVideo are affected by CVE-2026-56341?

AVideo versions prior to 26.0 are affected by CVE-2026-56341.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203