Authorization Bypass in WWBN AVideo Through Unbound Tokens
CVE-2026-59256

8.7HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-59256?

In WWBN AVideo, an authorization bypass vulnerability exists due to the improper handling of tokens generated by the getToken() function. This function creates tokens that are not bound to any user identity or specific purpose. During the process, valid tokens are issued to unauthenticated visitors via the plugin/Gallery/view/sections.php endpoint. Consequently, attackers can exploit this flaw by obtaining tokens from the Gallery endpoint and utilizing them to bypass authorization checks in other subsystems, such as view/hls.php, thus gaining unauthorized access to restricted video content.

Affected Version(s)

AVideo 0 <= 9c39d8c8b4c1f75540788d6b391740852ceb0732

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.