CVE-2026-84481 WWBN AVideo through 30.0 contains an information… — CVE Notify — TG.ME

🚨 CVE-2026-84481
WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to plugin/MobileManager/getConfiguration.json.php to obtain TLS private key file paths, socket configuration details, platform version, and debug flags enabling further targeted attacks.

🎖@cveNotify
GitHub
Unauthenticated MobileManager configuration disclosure exposes TLS key paths and socket config
WWBN/AVideo: `plugin/MobileManager/getConfiguration.json.php` returns the full MobileManager / YPTSocket configuration to any unauthenticated visitor. Root cause: the endpoint only checks that the...
September 1, 2026 13