---
id: CVE-2026-72748
title: >-
  AVideo contains an unauthenticated arbitrary file write vulnerability in the
  aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up
  to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests
  withou…
summary: >-
  AVideo contains an unauthenticated arbitrary file write vulnerability in the
  aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up
  to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests
  withou…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-306
published: '2026-08-11'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:32:39.347'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-72748'
references:
  - url: >-
      https://github.com/WWBN/AVideo/commit/1b55a9b3c4911d2f31594ce2e60566c70c6b95e8
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-v7p7-jccx-h37c'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/avideo-unauthenticated-arbitrary-file-write-via-avideoencoderchunk-json-php
    label: disclosure@vulncheck.com
  - url: 'https://github.com/WWBN/AVideo/security/advisories/GHSA-v7p7-jccx-h37c'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.01189
epssPercentile: 0.66558
ingestedAt: '2026-09-08T21:11:12.275Z'
---

## Overview

AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to write up to 4 GB of arbitrary content to the server filesystem via HTTP PUT requests without authentication. Attackers can exhaust disk space causing denial of service, poison the video encoding pipeline, or chain this with local file inclusion to achieve remote code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
