Unauthenticated Credential Submission Vulnerability in WWBN AVideo
CVE-2026-82643
6.9MEDIUM
What is CVE-2026-82643?
An unauthenticated credential submission vulnerability exists in WWBN AVideo's Live API endpoint located at plugin/Live/api/preauthorize.json.php. This flaw permits the submission of user credentials via GET requests without the implementation of rate limiting controls. Consequently, attackers can exploit this weakness to repeatedly submit valid credentials, resulting in unchecked two-factor confirmation email triggers. This allows for sustained password guessing attacks against user accounts, posing significant risks to user security.
