Authorization Bypass in WWBN AVideo Through Unbound Tokens
CVE-2026-59256
8.7HIGH
What is CVE-2026-59256?
In WWBN AVideo, an authorization bypass vulnerability exists due to the improper handling of tokens generated by the getToken() function. This function creates tokens that are not bound to any user identity or specific purpose. During the process, valid tokens are issued to unauthenticated visitors via the plugin/Gallery/view/sections.php endpoint. Consequently, attackers can exploit this flaw by obtaining tokens from the Gallery endpoint and utilizing them to bypass authorization checks in other subsystems, such as view/hls.php, thus gaining unauthorized access to restricted video content.
Affected Version(s)
AVideo 0 <= 9c39d8c8b4c1f75540788d6b391740852ceb0732
