LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-41064

CVE-2026-41064 - Vulnerability Analysis

CriticalCVSS: 9.3

Last Updated: April 22, 2026

WWBN AVideo - Command Injection

Published: April 22, 2026Updated: April 22, 2026Remote Exploitable

Overview

WWBN AVideo <= 29.0 contains a command injection caused by incomplete sanitization of URL inputs in file_get_contents and curl code paths, letting attackers execute arbitrary commands, exploit requires crafted URL input.

Severity & Score

Severity: Critical
CVSS Score: 9.3
EPSS Score: 0.0%(Probability of exploitation in next 30 days)

Impact

Attackers can execute arbitrary commands on the server, potentially leading to full system compromise.

Mitigation

Update to the version including commit 78bccae74634ead68aa6528d631c9ec4fd7aa536 or later.

Social Media Activity(2 posts)

OffSequence
OffSequence
@offseq
Apr 22, 2026

🛑 CRITICAL: WWBN AVideo <=29.0 vulnerable to OS command injection (CVE-2026-41064, CVSS 9.3). Unauthenticated attackers can exploit weak URL validation to run arbitrary commands. No official patch — see commit for fix details. https://radar.offseq.com/threat/cve-2026-41064-cwe-78-improper-neutralization-of-s-446caa6f #OffSeq #CVE202641064 #infosec

View original post
OffSequence
OffSequence
@offseq
Apr 22, 2026

🛑 CRITICAL: WWBN AVideo <=29.0 vulnerable to OS command injection (CVE-2026-41064, CVSS 9.3). Unauthenticated attackers can exploit weak URL validation to run arbitrary commands. No official patch — see commit for fix details. https://radar.offseq.com/threat/cve-2026-41064-cwe-78-improper-neutralization-of-s-446caa6f #OffSeq #CVE202641064 #infosec

View original post

Details

CVE ID
CVE-2026-41064
Severity
Critical
CVSS Score
9.3
Type
command_injection
Status
new
EPSS
0.0%
Social Posts
2

CWE

  • CWE-78

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

EPSS Score

0.0%Probability of exploitation in the next 30 days