CVE-2026-91966 UNKNOWN

CVE-2026-91966

Published: 2026-09-15

Description

AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe internal network hosts and ports, following redirects without authentication.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…