Authorization Bypass Vulnerability in WWBN AVideo Product
CVE-2026-58002

7.1HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-58002?

The vulnerability in WWBN AVideo arises from an authorization bypass in the Users_affiliations add.json.php endpoint. This flaw permits authenticated users to create forged two-party consent records by manipulating the counterparty's agreement timestamp. Attackers exploiting this vulnerability can establish fraudulent affiliations with a status of 'a', enabling them to reassign video ownership to arbitrary users via the videoAddNew.json.php endpoint, which incorrectly trusts the manipulated affiliation as a valid authorization mechanism.

Affected Version(s)

AVideo 0 <= 9c39d8c8b4c1f75540788d6b391740852ceb0732

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.