Authentication Bypass Vulnerability in AVideo by WWBN
CVE-2026-59808
8.7HIGH
What is CVE-2026-59808?
AVideo has a significant authentication bypass flaw that allows attackers with upload permissions to exploit the deduplicateByEncoderQueueId() function. This vulnerability enables them to retrieve sensitive video_id_hash credentials for any video based solely on the encoder_queue_id, circumventing the necessary ownership verification. By omitting the videos_id parameter in their requests, attackers can gain unauthorized access to an administrator's session as the video owner, effectively allowing them to manipulate system configurations and potentially compromise the integrity of the entire platform.
Affected Version(s)
AVideo 0 <= 9c39d8c8b4c1f75540788d6b391740852ceb0732
