SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82647

MEDIUM · CVSS 6.1 EPSS 0.10% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-30 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability exists in the sendEmail.json.php file of WWBN AVideo, allowing authenticated administrators to be exploited via cross-site request forgery. Attackers can leverage this flaw to send emails from the site's contact address, bypassing origin checks and captcha validation, which can facilitate phishing and brand impersonation attacks. Organizations using AVideo should prioritize addressing this vulnerability to protect against potential misuse by malicious actors.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82647
Severity
MEDIUM
CVSS
6.1
EPSS
0.10%

Original NVD Description

WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation. Attackers can craft a malicious web page that, when visited by an authenticated admin, sends emails with attacker-controlled subject and body to arbitrary recipients, passing SPF/DKIM/DMARC validation for phishing and brand impersonation attacks.