CVE-2026-56342: AVideo - Server-Side Request Forgery in Live/test.php via statsURL Parameter

Published Jun 20, 2026
·
Updated

AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators to read arbitrary URLs via the statsURL parameter, which lacks isSSRFSafeURL() validation and accepts requests to private IP ranges and cloud metadata endpoints. Attackers can exploit this by crafting requests to internal services, cloud metadata endpoints like 169.254.169.254, and localhost to retrieve sensitive information including IAM credentials, internal service responses, and network configuration details.

Affected Software

1 affected component
AVideo AVideo<=27.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Modify plugin/Live/test.php to validate the statsURL parameter using isSSRFSafeURL() and reject or sanitize any statsURL that resolves to private IP ranges or known cloud metadata endpoints such as 169.254.169.254.

    AVideo plugin/Live/test.php statsURL validation = apply isSSRFSafeURL() validation; block requests that resolve to private IP ranges and cloud metadata endpoints (e.g., 169.254.169.254)
  2. Operational

    Audit logs for any requests made via plugin/Live/test.php to internal addresses or cloud metadata endpoints (including 169.254.169.254). If IAM credentials, secrets, or other sensitive data may have been exposed, rotate those IAM credentials and any exposed secrets immediately.

Event History

Jun 20, 2026
CVE Published
via MITRE·06:27 PM
Data Sourced
via MITRE·06:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2026-56342?

CVE-2026-56342 has a severity rating of medium, with a score of 6.8.

2

How does CVE-2026-56342 affect AVideo?

CVE-2026-56342 affects AVideo versions through 27.0 by allowing authenticated administrators to exploit server-side request forgery in live/test.php.

3

What can exploit CVE-2026-56342?

CVE-2026-56342 can be exploited by sending crafted requests through the statsURL parameter, which processes insufficient validation.

4

Is there a patch available for CVE-2026-56342?

As of now, there is no information provided about a patch for CVE-2026-56342.

5

What can an attacker achieve by exploiting CVE-2026-56342?

An attacker can use CVE-2026-56342 to read arbitrary internal URLs or sensitive data within the private network.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203