CVE-2026-84478 Overview
WWBN AVideo contains a path traversal vulnerability in the get_api_login_code API endpoint. Unauthenticated attackers can supply directory traversal sequences in the code parameter to delete arbitrary .log files on the server. The flaw enables destruction of audit logs and information disclosure about filesystem contents through error-based probing. The vulnerability is classified under CWE-73: External Control of File Name or Path.
Critical Impact
Unauthenticated attackers can delete arbitrary .log files on affected AVideo installations, destroying forensic evidence and enabling filesystem enumeration through response differentials.
Affected Products
- WWBN AVideo (open-source video streaming platform)
- Installations exposing the get_api_login_code API endpoint
- Refer to the GitHub Security Advisory GHSA-wh69-gqmj-rcqg for version-specific details
Discovery Timeline
- 2026-09-01 - CVE-2026-84478 published to NVD
- 2026-09-01 - Last updated in NVD database
Technical Details for CVE-2026-84478
Vulnerability Analysis
The vulnerability resides in the get_api_login_code endpoint of WWBN AVideo. The endpoint accepts a code parameter that is used to construct a filesystem path pointing to a .log file targeted for deletion. Input from the code parameter is not properly validated or sanitized against directory traversal sequences such as ../.
An unauthenticated attacker can submit crafted values through the code parameter to escape the intended directory and reference .log files elsewhere on the filesystem. The application then performs a delete operation against the resolved path. Because the endpoint does not require authentication, the attack surface extends to any network-reachable AVideo instance.
Beyond destructive impact, the endpoint's response behavior differs based on whether the referenced file exists. An attacker can iterate through candidate paths and infer the presence of files, effectively turning the flaw into a filesystem enumeration primitive.
Root Cause
The root cause is external control of a file path parameter without canonicalization or allow-list validation. The endpoint trusts client-supplied input to determine which file the server operates on. This maps to CWE-73, where attacker-controlled input directly influences a file path used in a sensitive operation.
Attack Vector
Exploitation is remote and unauthenticated over the network. An attacker sends an HTTP request to the get_api_login_code endpoint with a code parameter containing traversal sequences that resolve to a target .log file. No user interaction is required. Refer to the VulnCheck advisory on AVideo arbitrary log file deletion for a full technical walkthrough.
Detection Methods for CVE-2026-84478
Indicators of Compromise
- HTTP requests to the get_api_login_code endpoint containing ../ or URL-encoded traversal sequences (%2e%2e%2f) in the code parameter.
- Unexpected deletion or truncation of .log files, particularly application audit logs and access logs.
- Anomalous 404 or error responses correlated with sequential code parameter probing from a single source IP.
Detection Strategies
- Inspect web server and reverse proxy logs for requests to get_api_login_code with suspicious code values.
- Deploy web application firewall (WAF) rules that flag directory traversal patterns targeting AVideo API endpoints.
- File integrity monitoring on the AVideo log directory to identify unauthorized deletions.
Monitoring Recommendations
- Forward web server access logs and AVideo application logs to a centralized SIEM for correlation and retention outside the affected host.
- Alert on high-volume requests to get_api_login_code from a single client, which suggests enumeration attempts.
- Track deletion events on the log directory using host-level auditing such as auditd or equivalent.
How to Mitigate CVE-2026-84478
Immediate Actions Required
- Upgrade AVideo to a patched release as identified in the GitHub Security Advisory GHSA-wh69-gqmj-rcqg.
- Restrict network access to the AVideo administrative and API endpoints using firewall rules or reverse proxy allow-lists.
- Audit existing log files for signs of deletion or tampering and restore from backups where necessary.
Patch Information
The vendor has published a security advisory at GHSA-wh69-gqmj-rcqg. Apply the fixed release referenced in the advisory. Additional exploitation context is available in the VulnCheck advisory.
Workarounds
- Block requests to get_api_login_code at the reverse proxy or WAF until the patch is applied.
- Add WAF signatures that reject code parameter values containing ../, ..\\, or their encoded variants.
- Ship AVideo logs to a remote log store in real time so local deletion does not eliminate forensic evidence.
# Example nginx snippet to block traversal patterns targeting the vulnerable endpoint
location ~* /get_api_login_code {
if ($arg_code ~* "(\.\./|\.\.%2f|%2e%2e/)") {
return 403;
}
}
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.