Access Control Vulnerability in WWBN AVideo Product
CVE-2026-85156
6.9MEDIUM
What is CVE-2026-85156?
WWBN AVideo exhibits a vulnerability in which it inadequately validates access controls on the public channel page. This flaw allows unauthenticated users to view both unlisted and group-restricted videos due to hardcoded visibility flags and an undefined property. Attackers can exploit this weakness by accessing the channel endpoint, potentially retrieving sensitive video content that should remain hidden from the public. This includes full URLs to unlisted videos and thumbnails of content restricted to members, regardless of the operator's settings to hide private videos.
Affected Version(s)
AVideo 0 <= 29.0
