SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-84482

HIGH · CVSS 8.8 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-01 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability allows attackers to exploit cross-site request forgery in the get_domain() and isSameDomain() functions of WWBN AVideo, enabling unauthorized administrative actions, including modifications to live server configurations. This poses a significant risk to systems using AVideo, particularly those with multiple subdomains or complex domain setups. Organizations utilizing this software should prioritize patching to mitigate potential unauthorized access and configuration changes.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-84482
Severity
HIGH
CVSS
8.8
EPSS
0.14%

Original NVD Description

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes including live server configuration changes.