{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-72748/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-72748"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AVideo (29.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","rce","file-write","cve-2026-72748","web-application","xss","injection"],"_cs_type":"advisory","_cs_vendors":["WWBN"],"content_html":"\u003cp\u003eAVideo, an open-source video platform, contains a critical vulnerability (CVE-2026-72748) in the \u003ccode\u003eaVideoEncoderChunk.json.php\u003c/code\u003e endpoint. This vulnerability allows remote, unauthenticated attackers to perform an arbitrary file write to the server's filesystem using HTTP PUT requests. The flaw permits the upload of files up to 4 GB in size. This can be used by attackers to exhaust server disk space (causing a denial-of-service condition), poison the video encoding pipeline, or, if chained with local file inclusion (LFI) vulnerabilities, achieve remote code execution. Defenders should prioritize patching or restricting access to the affected endpoint immediately.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an AVideo instance reachable over the network.\u003c/li\u003e\n\u003cli\u003eAttacker probes the target for the presence of the \u003ccode\u003eaVideoEncoderChunk.json.php\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker sends a crafted HTTP PUT request to the target endpoint without providing authentication credentials.\u003c/li\u003e\n\u003cli\u003eThe vulnerable endpoint accepts the payload, writing it to the server's local filesystem.\u003c/li\u003e\n\u003cli\u003eAttacker iterates the request to maximize disk space usage, inducing a denial-of-service state.\u003c/li\u003e\n\u003cli\u003eAttacker overwrites existing application logic or uploads a web shell to the server.\u003c/li\u003e\n\u003cli\u003eAttacker executes the uploaded payload to gain arbitrary code execution on the underlying host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-72748 can result in total compromise of the AVideo server. Potential impacts include complete loss of availability through disk exhaustion, unauthorized data modification via pipeline poisoning, and full system takeover via remote code execution. Organizations using AVideo version 29.0 and below are susceptible to these risks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate AVideo to the latest patched version available from the WWBN repository to remediate CVE-2026-72748.\u003c/li\u003e\n\u003cli\u003eApply the vendor-provided security patch immediately: \u003ca href=\"https://github.com/WWBN/AVideo/commit/1b55a9b3c4911d2f31594ce2e60566c70c6b95e8\"\u003ehttps://github.com/WWBN/AVideo/commit/1b55a9b3c4911d2f31594ce2e60566c70c6b95e8\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP PUT requests targeting \u003ccode\u003eaVideoEncoderChunk.json.php\u003c/code\u003e from unauthorized or unexpected IP addresses.\u003c/li\u003e\n\u003cli\u003eRestrict access to the \u003ccode\u003eaVideoEncoderChunk.json.php\u003c/code\u003e endpoint at the web application firewall (WAF) or ingress proxy level to authenticated users only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-11T14:03:21Z","date_published":"2026-08-11T14:02:13Z","id":"https://feed.craftedsignal.io/briefs/2026-08-avideo-arbitrary-file-write/","summary":"An unauthenticated arbitrary file write vulnerability (CVE-2026-72748) in the AVideo aVideoEncoderChunk.json.php endpoint allows remote attackers to upload arbitrary content to the server, potentially leading to remote code execution.","title":"Unauthenticated Arbitrary File Write in AVideo","url":"https://feed.craftedsignal.io/briefs/2026-08-avideo-arbitrary-file-write/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-72748","version":"https://jsonfeed.org/version/1.1"}