Authorization Bypass Vulnerability in WWBN AVideo Product
CVE-2026-58002
7.1HIGH
What is CVE-2026-58002?
The vulnerability in WWBN AVideo arises from an authorization bypass in the Users_affiliations add.json.php endpoint. This flaw permits authenticated users to create forged two-party consent records by manipulating the counterparty's agreement timestamp. Attackers exploiting this vulnerability can establish fraudulent affiliations with a status of 'a', enabling them to reassign video ownership to arbitrary users via the videoAddNew.json.php endpoint, which incorrectly trusts the manipulated affiliation as a valid authorization mechanism.
Affected Version(s)
AVideo 0 <= 9c39d8c8b4c1f75540788d6b391740852ceb0732
