OAuth Vulnerability in AVideo Open Source Video Platform
CVE-2026-43875

6.8MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-43875?

An OAuth vulnerability exists in the AVideo open source video platform that allows attackers to bypass password hashing during the authentication process. When a user logs in, a redirect URL may expose their password hash due to improper handling of OAuth login responses. This vulnerability enables attackers to capture sensitive credentials through server logs or browser histories, potentially leading to full account takeover, including access to admin accounts. A patch for this issue has been implemented in later versions of AVideo.

Affected Version(s)

AVideo <= 29.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.