<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T16:40:02.234414+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-278493</id>
    <title>EUVD-2026-278493</title>
    <updated>2026-10-08T16:40:02.303749+00:00</updated>
    <content>EUVD-2026-278493</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-278493"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-34738</id>
    <title>fkie_cve-2026-34738</title>
    <updated>2026-10-08T16:40:02.303807+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an overrideStatus request parameter that allows any uploader to set a video's status to any valid state, including "active" (a). This bypasses the admin-controlled moderation and draft workflows. The setStatus() method validates the status code against a list of known values but does not verify that the caller has permission to set that particular status. As a result, any user with upload permissions can publish videos directly, circumventing content review processes. At time of publication, there are no publicly available patches.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-34738"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m577-w9j8-ch7j</id>
    <title>GHSA-m577-w9j8-ch7j — AVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request Parameter</title>
    <updated>2026-10-08T16:40:02.303881+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Packagist: wwbn/avideo</p>
<p>## Summary</p>
<p>AVideo's video processing pipeline accepts an `overrideStatus` request parameter that allows any uploader to set a video's status to any valid state, including "active" (`a`). This bypasses the admin-controlled moderation and draft workflows. The `setStatus()` method validates the status code against a list of known values but does not verify that the caller has permission to set that particular status. As a result, any user with upload permissions can publish videos directly, circumventing content review processes.</p>
<p>## Details</p>
<p>At `objects/video.php:1055-1056`, the video object checks for an `overrideStatus` parameter in the request and applies it directly:</p>
<p>```php
if (!empty($_REQUEST['overrideStatus'])) {
    return $this-&gt;setStatus($_REQUEST['overrideStatus']);
}
```</p>
<p>This code is reached from two entry points:
- `objects/videoAddNew.json.php:157` - when adding a new video
- `objects/aVideoEncoder.json.php:114` - when processing an encoded video</p>
<p>The `setStatus()` method validates that the provided status code is one of the recognized values (`a`, `k`, `i`, `h`, `e`, `x`, `d`, `t`, `u`, `s`, `r`, `f`, `b`, `p`, `c`) but does not perform any authorization check. It does not verify whether the calling user has permission to set a video to the requested status.</p>
<p>The relevant status codes include:
- `a` - Active (published and publicly visible)
- `k` - Draft (pending review)
- `i` - Inactive
- `e` - Encoding
- `x` - Deleted
- `u` - Unlisted</p>
<p>When an admin configu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m577-w9j8-ch7j"/>
  </entry>
</feed>
