{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-59256/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-58003"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AVideo (\u003c= commit 9c39d8c8)","AVideo (\u003c= 9c39d8c8)"],"_cs_severities":["high"],"_cs_tags":["web-application","csrf","cve-2026-58003","web-application-vulnerability","authorization-bypass","cve-2026-59256"],"_cs_type":"advisory","_cs_vendors":["WWBN"],"content_html":"\u003cp\u003eWWBN AVideo, an open-source video platform, contains a cross-site request forgery (CSRF) vulnerability tracked as CVE-2026-58003, affecting all versions through commit 9c39d8c8. The vulnerability resides in the 'releaseVideoNow.json.php' endpoint, which fails to implement necessary authenticity checks and erroneously accepts GET requests for state-changing operations.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this by enticing an authenticated administrator to visit a malicious webpage containing a crafted GET request. The request, when executed within the administrator's browser, uses the active session cookie to invoke the 'releaseVideoNow.json.php' endpoint. By manipulating the 'videos_id' parameter in this request, the attacker can force the permanent publication of videos that were intended to remain in an embargoed or private state. This vulnerability poses a significant risk to the integrity of sensitive video content managed on the platform.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies a target administrative user who is likely to have an active session in the AVideo application.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious URL pointing to the vulnerable 'releaseVideoNow.json.php' endpoint on the target AVideo server.\u003c/li\u003e\n\u003cli\u003eThe crafted URL includes the 'videos_id' parameter corresponding to an embargoed video the attacker intends to publish.\u003c/li\u003e\n\u003cli\u003eThe attacker delivers the malicious URL to the administrator via a phishing email, a compromised website, or an embedded iframe in a site visited by the administrator.\u003c/li\u003e\n\u003cli\u003eThe administrator, while logged into the AVideo application, clicks the link or visits the page containing the malicious request.\u003c/li\u003e\n\u003cli\u003eThe victim's browser automatically includes the legitimate AVideo session cookies with the GET request to the AVideo server.\u003c/li\u003e\n\u003cli\u003eThe AVideo server processes the request as a legitimate administrative action due to the presence of the session cookie.\u003c/li\u003e\n\u003cli\u003eThe embargoed video is permanently published on the platform without the administrator's knowledge or consent.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the unauthorized publication of embargoed or private video content. This can lead to the premature release of sensitive organizational, media, or proprietary information, potentially damaging the victim organization's reputation or violating distribution agreements. The scope includes any WWBN AVideo installation running the affected commit or earlier.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security patch provided by WWBN in the official GitHub repository for CVE-2026-58003 to mitigate the underlying endpoint vulnerability.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous GET requests directed to 'releaseVideoNow.json.php' that originate from referrers outside the expected application domain.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to inspect and challenge or block external requests to 'releaseVideoNow.json.php' that do not originate from authenticated application workflows.\u003c/li\u003e\n\u003cli\u003eEnable strict SameSite cookie attributes on application session cookies to mitigate the risk of cross-site request forgery.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-22T13:30:46Z","date_published":"2026-08-22T13:30:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wwbn-avideo-csrf/","summary":"WWBN AVideo versions through commit 9c39d8c8 contain a CSRF vulnerability in the releaseVideoNow.json.php endpoint that allows unauthenticated attackers to force administrative users to publish embargoed videos.","title":"CVE-2026-58003: Cross-Site Request Forgery in WWBN AVideo","url":"https://feed.craftedsignal.io/briefs/2026-08-wwbn-avideo-csrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-59256","version":"https://jsonfeed.org/version/1.1"}