LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-41058

CVE-2026-41058 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: April 21, 2026

WWBN AVideo - Path Traversal

Published: April 21, 2026Updated: April 21, 2026Remote Exploitable

Overview

WWBN AVideo <= 29.0 contains a path traversal caused by incomplete filtering of the CloneSite `deleteDump` GET parameter, letting attackers unlink arbitrary files via `../../` sequences, exploit requires crafted request.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can delete arbitrary files on the server, potentially disrupting service or causing data loss.

Mitigation

Update to the version including commit 3c729717c26f160014a5c86b0b6accdbd613e7b2 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Apr 21, 2026

🟠 CVE-2026-41058 - High (8.1) WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not apply path traversal filtering, allowing `unlink()` of arbitrary files via `../../` sequences in th... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-41058/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Apr 21, 2026

🟠 CVE-2026-41058 - High (8.1) WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not apply path traversal filtering, allowing `unlink()` of arbitrary files via `../../` sequences in th... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-41058/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-41058
Severity
High
CVSS Score
8.1
Type
path_traversal
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-22

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

EPSS Score

0.0%Probability of exploitation in the next 30 days