logo

Critical Zero-Click Command Injection in AVideo Platform Allows Stream Hijacking

ID: e3874be5-24a3-56c3-9735-24b398c1282b

STIX ID: report--e3874be5-24a3-56c3-9735-24b398c1282b

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-03-08

Date Updated: 2026-04-21

Author: Abinaya

...
...

**Executive Summary:** A critical zero-click command-injection vulnerability (CVE-2026-29058) in AVideo v6.0 allows unauthenticated attackers to execute arbitrary OS commands via a base64Url parameter in objects/getImage.php, potentially enabling full server compromise, credential exfiltration, and live-stream hijacking; AVideo 7.0+ contains the patch, and administrators should upgrade or apply mitigations such as IP allowlisting, WAF rules, or disabling the image retrieval endpoint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.