Unrestricted Authentication Vulnerability in WWBN AVideo
CVE-2026-86729

9.1CRITICAL

Key Information:

Vendor

Wwbn

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86729?

WWBN AVideo exposes a significant vulnerability through the get_api_preauthorize endpoint in its API, which allows brute-force attempts without any rate limiting. Unlike its counterpart, get_api_signIn, which restricts login attempts, this endpoint permits unlimited guesses on user credentials. The response mechanism further complicates security; it reveals whether a user ID is authenticated or not, in addition to returning the same 'Invalid credentials' message for both successful and failed login attempts. As a result, this flaw could lead to unauthorized access to user accounts, including admin accounts, posing a serious security risk for users of AVideo.

Affected Version(s)

AVideo 0 <= 29.0

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

rajivraj
.