A vulnerability was found in WWBN AVideo up to 28.x. It has been classified as problematic. This issue affects the function
execAsync of the file on_publish.php of the component Live plugin. This manipulation causes os command injection.
This vulnerability is handled as CVE-2026-64625. The attack can be initiated remotely. There is not any exploit available.