SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-84481

MEDIUM · CVSS 6.9 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The MobileManager plugin in WWBN AVideo versions up to 30.0 is vulnerable to information disclosure, allowing unauthenticated users to access sensitive configuration data through the getConfiguration endpoint. This exposure can reveal TLS private key file paths and other critical details, potentially facilitating further targeted attacks. Organizations using this plugin should prioritize patching to mitigate the risk of unauthorized access to sensitive information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84481
Severity
MEDIUM
CVSS
6.9
EPSS
0.26%

Original NVD Description

WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to plugin/MobileManager/getConfiguration.json.php to obtain TLS private key file paths, socket configuration details, platform version, and debug flags enabling further targeted attacks.