Authentication Bypass Vulnerability in AVideo by WWBN
CVE-2026-59808

8.7HIGH

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
22 August 2026

What is CVE-2026-59808?

AVideo has a significant authentication bypass flaw that allows attackers with upload permissions to exploit the deduplicateByEncoderQueueId() function. This vulnerability enables them to retrieve sensitive video_id_hash credentials for any video based solely on the encoder_queue_id, circumventing the necessary ownership verification. By omitting the videos_id parameter in their requests, attackers can gain unauthorized access to an administrator's session as the video owner, effectively allowing them to manipulate system configurations and potentially compromise the integrity of the entire platform.

Affected Version(s)

AVideo 0 <= 9c39d8c8b4c1f75540788d6b391740852ceb0732

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

santhreal
.