Access Control Vulnerability in WWBN AVideo Product
CVE-2026-85156

6.9MEDIUM

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85156?

WWBN AVideo exhibits a vulnerability in which it inadequately validates access controls on the public channel page. This flaw allows unauthenticated users to view both unlisted and group-restricted videos due to hardcoded visibility flags and an undefined property. Attackers can exploit this weakness by accessing the channel endpoint, potentially retrieving sensitive video content that should remain hidden from the public. This includes full URLs to unlisted videos and thumbnails of content restricted to members, regardless of the operator's settings to hide private videos.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.