A vulnerability identified as critical has been detected in WWBN AVideo. This affects an unknown function of the component Encoder. The manipulation of the argument downloadURL leads to server-side request forgery.

This vulnerability is referenced as CVE-2026-64626. Remote exploitation of the attack is possible. No exploit is available.